Safe Dollar Hack
What happened
The attacker's address:
https://polygonscan.com/address/0x8a0a1eb0…907c6c
The attack transaction:
https://polygonscan.com/tx/0x76c722c7…66b210
The re-entrance attack on the Token Locker smart contract was performed, Safe Dollar share tokens were affected.
The contract itself does not have an issue with standard ERC20, but since the PLX token is ERC777 standard, there will be tokenReceived() callback event every time method transfer() triggered. The attacking smart contract deployed by the hacker has included the unlockAll() trigger repeatedly (40 times) in the event, so he was able to unlock more than the amount he locked in before.
The attacker withdrew 9,959.26 SDS, then sold for 95,392 USDC after bridging all to Ethereum.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report safedollar.medium.com
- report Report polydex.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.