Rico Hack

Reported loss Not disclosed
Arbitrum
Arbitrary External Call

What happened

On April 20, 2024, the Rico Credit System's RCS0 deployment on Arbitrum was drained. The team said RCS0 had no funds left, turned off the UI and began shutting down the remaining ilks (collateral types). DeFiHackLabs puts the loss at about $36,000.

The entry point was the flash function on Rico's BankDiamond contract (0x598c6c1cd9459f882530fc9d7da438cb74c6cb3b), which let the caller make the bank call a token with calldata of the caller's choosing. Attacker: 0xc91cb089084f0126458a1938b794aa73b9f9189d. Attack transaction: 0x5d2a94785d95a740ec5f778e79ff014c880bcefec70d1a7c2440e611f84713d6.

How it happened

  1. The attacker called BankDiamond.flash(token, data) with a token address and calldata encoding transfer(attacker, bankBalance). The bank made that call itself, so it sent its own USDC, ARB, LINK, wstETH, WETH and bridged USDC.e balances to the attacker.
  2. For users who had approved BankDiamond to spend their tokens, the attacker passed calldata encoding transferFrom(user, attacker, amount), pulling USDC and wstETH straight from those wallets.
  3. The attacker swapped the non-USDC tokens to USDC on Uniswap V3.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.