Palm USD Hack
What happened
$900K USD Lost in USDP Staking and Liquidity Exploit.
The root cause appears to be a design error in the USDP project's staking mechanism, which supports adding and removing liquidity. While the calculation of LP token amounts is dynamic, the functions buyUSDP() and sellUSDP() do not exhibit the same dynamism. This oversight created an exploitable vulnerability.
The attacker capitalized on this flaw by staking a substantial amount and subsequently using buyUSDP() to purchase a large quantity of USDP tokens. Upon buying, the attacker was able to execute removeLiquidity(), which returned most of the funds in BUSDT back. However, a significant balance of USDP remained. The USDP to BUSDT exchange rate being 1:1 guaranteed the return of the money.
Attacker:
https://bscscan.com/address/0xf84efa8a…131366
Exploit tx:
https://bscscan.com/tx/0x62dba550…30eac9
Case & protocol details
Post-Incident Timeline
-
2023-07-28
PalmSwap announced return of the 80% of the stolen funds by WhiteHat on their Official Twitter
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.