Platypus Finance Hack

TOTAL LOST $52K
Low Reentrancy avalanche

What happened

Platypus Finance, an Avalanche-based DEX, was exploited in a reentrancy attack causing a loss of 51,840 $USD.

Platypus Finance faced an exploit that caused a loss of approximately $51k. The exploit emerged due to an issue with the liquidity conversion calculation for LP-USDC, which resulted in an excessively large quantity calculation for USDC.e when swapping USDC for USDC.e. The call to asset.addLiability() in the _deposit function caused an increase in the asset.liability() parameter in withdrawFrom, allowing the hacker to withdraw more USDC.e than the amount of USDC previously deposited.

The funds remain in the attacker's address, amounting to $31,120 worth of assets in Avalanche and $20,450 worth of $DAI in Ethereum chain.

Attacker Address:

https://showtrace.io/address/0xc64afc46…79521a

Malicious Transaction Example:

https://showtrace.io/tx/0x5e785b87…bab388

Malicious Contract Address:

https://showtrace.io/address/0x16a3c9e4…8f1ed8

Case & protocol details

Classification Exchange (DEX) / Protocol Logic
Protocol Type DEX
Affected asset / contract PTP
Smart Contract Language Solidity
Official Website platypus.finance/
Protocol Twitter/X @Platypusdefi

Security review history

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.