Quint Hack
Incident Overview
The Quint project was attacked by hackers in the amount of $130K. The attacker took advantage of the vulnerability, thanks to which he was able to withdraw his rewards again.
Quint is a stacking and farming platform where users can stake $QUINT at low transaction fees while enjoying the rewards in the form of a variety of tokens.
The attack occurred due to a vulnerability in the contract called by the reStake() function. When this function is performed, the reward time in LP tokens is not updated, as a result an attacker can claim the issued rewards several times.
Attacker account addresses:
1) https://bscscan.com/address/0x82f42c11…c87fca
2) https://bscscan.com/address/0xcBd00C9A…48117F
3) https://bscscan.com/address/0xa59D3d89…59992d
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Quint, these are the critical security checks that could have prevented this incident (June 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
-
01
Source 1 https://quint.io/
- 02
Learn to Prevent the Next Quint
The Quint hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.