pcash Hack
What happened
On May 6, 2023, PayCash, a stablecoin exchange on EOS, lost about $2 million when its main contract swap.pcash was exploited and its liquidity pools drained. The attacker, known on-chain as EOS account nrwgthbeupex, swapped the proceeds into roughly 2 million EOS. To stay out of reach of EOS mainnet governance, they moved the funds into EOS EVM, which then had no tooling for incident response, and spread them across more than 6,000 newly created accounts. The exploit's technical mechanism has not been published; CryptoDaily notes the project had not been audited.
The PayCash team covered user losses. The EOS Recover+ team then worked with EOS EVM engineers and PayCash on a recovery path: EOS EVM v0.5.2 added administrative actions that let block producers, through an approved multisig proposal, move funds from the attacker's EVM addresses to the eos.recover account. After a test on the Jungle testnet in January 2024, block producers executed the recovery on mainnet on February 22, 2024, returning nearly 2 million EOS (about $1.8 million at February 2024 prices).
Protocol details
Evidence
- code EOSRecover/pay-cash (GitHub README) github.com
- analysis DeFiLlama defillama.com
- analysis EOS's Recover+ Shares How They Recovered Nearly $2 Million in Stolen DeFi Assets dailycoin.com
- analysis EOS Recover+ Rides to the Rescue Following $1.8M PayCash Theft cryptodaily.co.uk
- analysis SlowMist Hacked - EOS category (pcash entry) hacked.slowmist.io
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.