Shezmu Hack
What happened
On September 21, 2024, Shezmu Yield Protocol suffered a $4.9M exploit due to a vulnerability in one of its vaults, enabling the attacker to mint unlimited ShezUSD.
A flaw in Shezmu’s vault mechanism allowed an attacker to arbitrarily mint ShezUSD, effectively creating an infinite supply. This exploit occurred shortly after a smart contract upgrade, suggesting a potential oversight in the update. The attacker took advantage of the unchecked minting mechanism, draining Shezmu’s liquidity.
In response, Shezmu offered a bug bounty, successfully negotiating the return of funds.
Case & protocol details
Security review history
- Spearbit Report
Evidence & learning
Sources and on-chain records
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.