Osmosis Hack
Incident Overview
Osmosis has been rugged by liquidity pool providers. Size of loss is ~$5M. One of the attackers added liquidity USDC and OSMO. The attacker then received GAMM LP tokens in return, which represented his share in the pool. They immediately revoked GAMM LP tokens, thereby receiving 50% more than the amount of USDC and OSMO that were added as liquidity.
Token address: https://www.mintscan.io/osmosis/account/osmo1w4x44ek799hvg97x0mfwu6gg5dww2r8fhkgrgj
Example transaction: https://www.mintscan.io/osmosis/account/osmo1hq8tlgq0kqz9e56532zghdhz7g8gtjymdltqer
Attack example step by step:
1. Add liquidity to a pool
2. Remove liquidity from the pool allowing 50% extra. No bonding needed.
3. Rinse and repeat
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Osmosis, these are the critical security checks that could have prevented this incident (June 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Osmosis
The Osmosis hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.