Platypus Finance Hack
What happened
Platypus Finance, an Avalanche-based DEX, was exploited in a reentrancy attack causing a loss of 51,840 $USD.
Platypus Finance faced an exploit that caused a loss of approximately $51k. The exploit emerged due to an issue with the liquidity conversion calculation for LP-USDC, which resulted in an excessively large quantity calculation for USDC.e when swapping USDC for USDC.e. The call to asset.addLiability() in the _deposit function caused an increase in the asset.liability() parameter in withdrawFrom, allowing the hacker to withdraw more USDC.e than the amount of USDC previously deposited.
The funds remain in the attacker's address, amounting to $31,120 worth of assets in Avalanche and $20,450 worth of $DAI in Ethereum chain.
Attacker Address:
https://showtrace.io/address/0xc64afc46…79521a
Malicious Transaction Example:
https://showtrace.io/tx/0x5e785b87…bab388
Malicious Contract Address:
https://showtrace.io/address/0x16a3c9e4…8f1ed8
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.