Palm USD Hack

TOTAL LOST $900K
Low Flash Loan Attacks

What happened

$900K USD Lost in USDP Staking and Liquidity Exploit.

The root cause appears to be a design error in the USDP project's staking mechanism, which supports adding and removing liquidity. While the calculation of LP token amounts is dynamic, the functions buyUSDP() and sellUSDP() do not exhibit the same dynamism. This oversight created an exploitable vulnerability.

The attacker capitalized on this flaw by staking a substantial amount and subsequently using buyUSDP() to purchase a large quantity of USDP tokens. Upon buying, the attacker was able to execute removeLiquidity(), which returned most of the funds in BUSDT back. However, a significant balance of USDP remained. The USDP to BUSDT exchange rate being 1:1 guaranteed the return of the money.

Attacker:

https://bscscan.com/address/0xf84efa8a…131366

Exploit tx:

https://bscscan.com/tx/0x62dba550…30eac9

Case & protocol details

Classification Stablecoin
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract USDP
Official Website www.paypal.com/pyusd
Protocol Twitter/X @PayPal

Post-Incident Timeline

  • 2023-07-28

    PalmSwap announced return of the 80% of the stolen funds by WhiteHat on their Official Twitter

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.