Shata Capital Hack
What happened
USDC vault owned by Shata Capital was exploited for about of 5M USD.
On February 24, 2023, an exploit was discovered in Shata Capital's EFVault contract, resulting in approximately $5.14 million in losses due to improper configuration after contract upgrade.
The attacker's address was 0xa0959536…743a0a and the attacked contract was 0x80cB7307…a2702c.
The attacker initially deposited 0.1 Ether to the EFVault contract 27 days prior to the attack to get a number of shares.
The EFVault contract had been upgraded by proxy before the attack, and the key parameter of the new function redeem in the upgraded contract was directly assigned by reading the wrong value from the corresponding storage location of the agent contract before the upgrade.
This resulted in an excessive amount of user withdrawable assets calculated in the redeem function, allowing the hacker to exploit this vulnerability and call the redeem function twice, profiting $3.43 million and $1.71 million respectively.
The vulnerability occurred because the initialize function of the newly implemented contract could not be called again after the upgrade, making it impossible to initialize the new variables.
In addition, the data storage structure of the old version was not taken into account when adding new variables in the new contract, which resulted in the new contract still reading the data of the proxy contract slot of 0xcc when reading the assetDecimal variable.
Through querying the transactions, it was found that the value of maxDeposit can be set by calling the setMaxDeposit function, and the latest value of maxDeposit was set to 5000000000000.
The attacker has exchanged all funds to ETH and transferred to tornado.cash.
Exploit TXs:
Exploiter:
Attacker contract:
Protocol details
Evidence
- report @CertiKAlert incident report twitter.com
- report @peckshield incident report twitter.com
- report Post-mortem medium.com
- analysis Web Archive archive.ph
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.