Pythia Hack

Reported loss $53K
Ethereum
Reentrancy

What happened

On 3 September 2024, an attacker drained about 21 ETH (around $53,000) from Pythia Finance's staking contract on Ethereum. QuillAudits reported the exploit. Cointelegraph describes Pythia as an algorithmic stablecoin project that planned to manage its treasury with AI.

The flaw was in how staking rewards were paid. The staking contract's verified source tracks rewards with a global rewards-per-share value (shareBasedPoints) and a per-holder pointsCorrection, and a claim pays shareBasedPoints times the holder's staked balance, adjusted by that correction. Staked positions (sPYTHIA) are ordinary ERC-20 tokens, and their transfers never call the contract's adjustPointsForTransfer helper. A fresh address that received sPYTHIA therefore had no correction and could claim rewards on its whole balance as if it had held it since the first distribution. The attacker (0xd861...74c0) used attack contract 0x5425...3647 to pass one staked position through a series of fresh helper contracts. Each helper claimed rewards on the full balance, and the attacker restaked what they collected. QuillAudits and Cointelegraph described the attack as a reentrancy on claimRewards. The public PoC, however, shows repeated claims across transferred balances rather than a callback loop.

How it happened

  1. The attacker's contract swapped 0.5 ETH for PYTHIA on Uniswap V2 and staked it, receiving sPYTHIA.
  2. It deployed a new helper contract and transferred its entire sPYTHIA balance to it.
  3. The helper called claimRewards(). Because the transfer had not updated pointsCorrection, the reward was the helper's full sPYTHIA balance times the accumulated shareBasedPoints. The helper then sent the PYTHIA rewards and the sPYTHIA back to the attack contract.
  4. The attack contract staked the new PYTHIA, which enlarged its position, and repeated steps 2-3 with a new helper, 30 times in the PoC.
  5. The inflated staked balance and rewards were cashed out, about 21 ETH (around $53K) in total.

Protocol details

Classification Reentrancy
Protocol Type DeFi Protocol
Implementation language Solidity
Protocol links Website @neirylab

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.