Rico Hack
What happened
On April 20, 2024, the Rico Credit System's RCS0 deployment on Arbitrum was drained. The team said RCS0 had no funds left, turned off the UI and began shutting down the remaining ilks (collateral types). DeFiHackLabs puts the loss at about $36,000.
The entry point was the flash function on Rico's BankDiamond contract (0x598c6c1cd9459f882530fc9d7da438cb74c6cb3b), which let the caller make the bank call a token with calldata of the caller's choosing. Attacker: 0xc91cb089084f0126458a1938b794aa73b9f9189d. Attack transaction: 0x5d2a94785d95a740ec5f778e79ff014c880bcefec70d1a7c2440e611f84713d6.
How it happened
- The attacker called
BankDiamond.flash(token, data)with a token address and calldata encodingtransfer(attacker, bankBalance). The bank made that call itself, so it sent its own USDC, ARB, LINK, wstETH, WETH and bridged USDC.e balances to the attacker. - For users who had approved
BankDiamondto spend their tokens, the attacker passed calldata encodingtransferFrom(user, attacker, amount), pulling USDC and wstETH straight from those wallets. - The attacker swapped the non-USDC tokens to USDC on Uniswap V3.
Protocol details
Evidence
- code DeFiHackLabs README entry: 20240420 Rico - Arbitrary Call github.com
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs Rico_exp.sol PoC raw.githubusercontent.com
- analysis Rico Credit System: RCS0 has been drained (X post, via fxtwitter mirror) api.fxtwitter.com
- analysis Louis Tsai on the Rico drain (X post, via fxtwitter mirror) api.fxtwitter.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.