PolyYeld Finance Hack
What happened
PolyYeld finance introduced a transfer fee, which was inconsistent with its masterchef contract. The resulting vulnerability was exploited by an attacker for $250k.
PolyYeld Finance is a yield aggregator protocol on the Polygon network. PolyYield introduced the $xYELD token, a deflationary token in order to support its yield aggregator services. A fee was applied on the transfers of the $xYELD token.
The PolyYeld Masterchef contract was not designed to support this token type, which created an exploit opportunity. After a series of deposits and withdraws, the $xYELD balance of the Masterchef became 1 WEI. The calculation of the $YELD rewards were based on the xYELD balance of the pool.
This referral mechanism generated $YELD 49B tokens to the attackers address. The attacker dumped a part of his balance in order to receive $ETH 123. The funds were then bridged and transferred through Tornado.cash.
The attacker's address:
https://polygonscan.com/address/0xa4bc39ff…9f5c01
The transaction behind the hack:
https://polygonscan.com/tx/0x3c143d2a…aca974
Case & protocol details
Security review history
- Paladin Security Report
Evidence & learning
Sources and on-chain records
- report Report polyyeldfinance.medium.com
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.