Pine Protocol Hack

Reported loss $95K
Ethereum
Swap Logic Flaw

What happened

Pine Protocol, an NFT-backed lending protocol on Ethereum, lost about 40 ETH (roughly $90,000) on December 21, 2023 (UTC). After an upgrade, the old and new versions of its lending pool contracts drew on the same fund vault. The old pool's flashLoan did not enforce the whitelistedIntermediaries check that the new version had.

The attacker borrowed WETH against an NFT, used a flash loan from the old pool to repay the loan in the new pool, and the one repayment also counted as the flash-loan repayment, since both went back into the same vault. This cleared the loan and freed the NFT while the attacker kept the borrowed WETH, and it repeated the cycle several times. The exploiter had funded its address with ETH withdrawn from FixedFloat and ChangeNOW, and it later sent 20 ETH to Tornado Cash.

In on-chain messages it said it would keep half of the funds as a bounty. Pine thanked it and asked for the rest to be returned to its multisig. MistTrack said the exploiter appeared to have received part of a bounty.

How it happened

  1. The attacker bought a Pudgy Penguins (PPG) NFT and borrowed about 4 WETH against it from Pine's new lending pool, which drew on the shared vault.
  2. Through an attack contract, it took a flash loan of the vault's WETH from the old lending pool.
  3. Inside the flash-loan callback, it used the borrowed WETH to call repay on the new pool. That cleared the NFT loan and sent the WETH back into the same vault.
  4. It topped up the vault with a small amount (about 0.3 WETH in the PoC) so the old pool's balance check passed. The one repayment was therefore counted both as the loan repayment and as the flash-loan return.
  5. The attacker now held the NFT and the originally borrowed WETH, and repeated the borrow-and-fake-repay cycle several times to drain about 40 ETH.

Protocol details

Classification Protocol Logic
Protocol Type NFT Lending
Implementation language Solidity
Protocol links Website @PineProtocol

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.