Osmosis Hack
What happened
Osmosis has been rugged by liquidity pool providers. Size of loss is ~$5M. One of the attackers added liquidity USDC and OSMO. The attacker then received GAMM LP tokens in return, which represented his share in the pool. They immediately revoked GAMM LP tokens, thereby receiving 50% more than the amount of USDC and OSMO that were added as liquidity.
Token address: https://www.mintscan.io/osmosis/account/osmo1w4x44ek799hvg97x0mfwu6gg5dww2r8fhkgrgj
Example transaction: https://www.mintscan.io/osmosis/account/osmo1hq8tlgq0kqz9e56532zghdhz7g8gtjymdltqer
Attack example step by step:
- Add liquidity to a pool
- Remove liquidity from the pool allowing 50% extra. No bonding needed.
- Rinse and repeat
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.