Platypus Finance Hack

TOTAL LOST $8.5M
Medium Flash Loan Attacks avalanche

What happened

Platypus Finance protocol was exploited via flash loan attack for 8,500,887 $USD. The attacker managed to bridge the part of the stolen amount.

Platypus Finance is an AMM that provides stableswap opportunities. The attacker exploited multiple asset contracts of the protocol, using a malicious smart contract with unverified source code. 8,500,887 $USD worth of assets in stablecoins such as nearly 4,400,000 $USDC, 2,700,000 $USDT, 687,000 $BUSD, and 691,000 $DAI were stolen.

The attacker used the USP solvency check mechanism's weakness and took 44,000,000 $USDC as a flash loan and performed malicious actions. This amount was used to swap for 44,000,000 Platypus LP-USD, and then to mint 41,700,000 $USP tokens for free. The $USP tokens then were swapped for various stablecoins.

It's said on the project's official Twitter that they are working with third parties such as Binance, Tether, and Circle to freeze the funds, and at the moment, $USDT was frozen. The malicious actor managed to bridge 2,403,165 $USDC through Gnosis Proxy.

Malicious transaction:

https://snowtrace.io/tx/0x1266a937…79b430

Attacker's address:

https://snowtrace.io/address/0xeff003d6…953958

Malicious contract:

https://snowtrace.io/address/0x67afdd64…8a5322

Transfer transactions:

https://snowtrace.io/tx/0x5e3eb070…d2d5c3

https://snowtrace.io/tx/0x76ceab91…e4ed5a

Case & protocol details

Classification Ecosystem / Exchange (DEX) / Protocol Logic
Protocol Type DEX
Affected asset / contract PTP
Smart Contract Language Solidity
Official Website platypus.finance/
Protocol Twitter/X @Platypusdefi

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.