Palm USD Hack
Incident Overview
$900K USD Lost in USDP Staking and Liquidity Exploit.
The root cause appears to be a design error in the USDP project's staking mechanism, which supports adding and removing liquidity. While the calculation of LP token amounts is dynamic, the functions buyUSDP() and sellUSDP() do not exhibit the same dynamism. This oversight created an exploitable vulnerability.
The attacker capitalized on this flaw by staking a substantial amount and subsequently using buyUSDP() to purchase a large quantity of USDP tokens. Upon buying, the attacker was able to execute removeLiquidity(), which returned most of the funds in BUSDT back. However, a significant balance of USDP remained. The USDP to BUSDT exchange rate being 1:1 guaranteed the return of the money.
Attacker:
https://bscscan.com/address/0xf84efa8a…131366
Exploit tx:
https://bscscan.com/tx/0x62dba550…30eac9
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Palm USD, these are the critical security checks that could have prevented this incident (July 2023).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialPost-Incident Timeline
-
2023-07-28
PalmSwap announced return of the 80% of the stolen funds by WhiteHat on their Official Twitter
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Palm USD
The Palm USD hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.