Platypus Finance Hack
What happened
Platypus Finance protocol was exploited via flash loan attack for 8,500,887 $USD. The attacker managed to bridge the part of the stolen amount.
Platypus Finance is an AMM that provides stableswap opportunities. The attacker exploited multiple asset contracts of the protocol, using a malicious smart contract with unverified source code. 8,500,887 $USD worth of assets in stablecoins such as nearly 4,400,000 $USDC, 2,700,000 $USDT, 687,000 $BUSD, and 691,000 $DAI were stolen.
The attacker used the USP solvency check mechanism's weakness and took 44,000,000 $USDC as a flash loan and performed malicious actions. This amount was used to swap for 44,000,000 Platypus LP-USD, and then to mint 41,700,000 $USP tokens for free. The $USP tokens then were swapped for various stablecoins.
It's said on the project's official Twitter that they are working with third parties such as Binance, Tether, and Circle to freeze the funds, and at the moment, $USDT was frozen. The malicious actor managed to bridge 2,403,165 $USDC through Gnosis Proxy.
Malicious transaction:
https://snowtrace.io/tx/0x1266a937…79b430
Attacker's address:
https://snowtrace.io/address/0xeff003d6…953958
Malicious contract:
https://snowtrace.io/address/0x67afdd64…8a5322
Transfer transactions:
https://snowtrace.io/tx/0x5e3eb070…d2d5c3
https://snowtrace.io/tx/0x76ceab91…e4ed5a
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference cryptoslate.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.