Platypus Finance Hack
Incident Overview
Platypus Finance protocol was exploited via flash loan attack for 8,500,887 $USD. The attacker managed to bridge the part of the stolen amount.
Platypus Finance is an AMM that provides stableswap opportunities. The attacker exploited multiple asset contracts of the protocol, using a malicious smart contract with unverified source code. 8,500,887 $USD worth of assets in stablecoins such as nearly 4,400,000 $USDC, 2,700,000 $USDT, 687,000 $BUSD, and 691,000 $DAI were stolen.
The attacker used the USP solvency check mechanism's weakness and took 44,000,000 $USDC as a flash loan and performed malicious actions. This amount was used to swap for 44,000,000 Platypus LP-USD, and then to mint 41,700,000 $USP tokens for free. The $USP tokens then were swapped for various stablecoins.
It's said on the project's official Twitter that they are working with third parties such as Binance, Tether, and Circle to freeze the funds, and at the moment, $USDT was frozen. The malicious actor managed to bridge 2,403,165 $USDC through Gnosis Proxy.
Malicious transaction:
https://snowtrace.io/tx/0x1266a937…79b430
Attacker's address:
https://snowtrace.io/address/0xeff003d6…953958
Malicious contract:
https://snowtrace.io/address/0x67afdd64…8a5322
Transfer transactions:
https://snowtrace.io/tx/0x5e3eb070…d2d5c3
https://snowtrace.io/tx/0x76ceab91…e4ed5a
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Platypus Finance, these are the critical security checks that could have prevented this incident (February 2023).
- Verify all logic paths related to Flashloan Reentrancy Attack / Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Check that all state-changing functions follow the Checks-Effects-Interactions (CEI) pattern to prevent reentrancy and logic ordering bugs
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Omniscia Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
- Twitter/X Alert https://twitter.com/peckshield/status/1626367531480125440
- Twitter/X Alert https://twitter.com/spreekaway/status/1626319585040338953
Sources & References
Learn to Prevent the Next Platypus Finance
The Platypus Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.