Soda Protocol Hack

Reported loss $160K
Ethereum
Withdrawal Logic Flaw

What happened

On September 20, 2020, one day after its contracts went live, attackers exploited the Soda.Finance lending pool on Ethereum. Anyone could liquidate healthy WETH loans because a wrong variable in WETHCalculator.sol made the liquidation check in collectDebt() always pass. AnChain.AI reported that more than 400 ETH (around $160,000) was liquidated from the pool.

The Soda team counted 17 affected addresses, 12 of which had a total of 448.339 WETH in locked principal liquidated. Because borrowers kept the SoETH they had borrowed against that collateral, the team put the victims' actual loss at 134.5017 WETH, about 30% of the principal. It offered to compensate victims for that 30% in SoETH from the SodaDev pool, offered a 1 ETH reward to the Weibo user who first found and reported the bug, and said it was preparing a full security audit.

How it happened

  1. Soda let users lock WETH as collateral and borrow SoETH up to a maximum loan-to-value (15-95%).
  2. collectDebt() let a third party liquidate a loan only when loanTotal >= maximumLoan. maximumLoan should have been computed from the loan's lockedAmount (the collateral).
  3. The code computed it from amount (the borrowed principal) instead. Since loanTotal is principal plus interest and the LTV factor is below 1, the check passed for every loan.
  4. Attackers called collectDebt() on healthy loans and liquidated 448.339 WETH of locked principal from 12 addresses, per the team's count.
  5. The team patched the contract, replacing amount with lockedAmount in the calculation.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.