Rikkei Finance Hack

TOTAL LOST $1.1M
Medium Access Control Attacks bsc

What happened

The Rikkei Finance project was exploited by a hacker who replaced the main price oracle with a malicious one due to the lack of access measures in SetOracleData, which led to the loss of $1.1M.

Rikkei Finance is a DeFi lending and borrowing protocol and an NFT Marketplace.

The attacker deployed a fake ChainLink contract, taking advantage of the vulnerability to replace the real ChainLink address with a fake one. The attacker created a smart contract that was used to carry out an attack on the project in this transaction:

https://bscscan.com/tx/0xb6601325…3399dd

After creating the contract, the attacker called the function "0x21e85463" which caused a number of transactions to empty the protocol. All the stolen funds were laundered via Tornado.Cash.

Attacker address: https://bscscan.com/address/0x803e0930…c093ab

Attacker contract addresses:

  1. Address
  2. Address

Attack transaction: https://bscscan.com/tx/0x93a9b022…687492

Case & protocol details

Classification NFT,Borrowing and Lending / Access Control
Protocol Type Lending
Affected asset / contract RIFI
Smart Contract Language Solidity
Protocol Twitter/X @rikkeifinance

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.