Starlay Finance Hack

Reported loss $2.1M
Acala
Redeem Logic Flaw

What happened

On February 8, 2024, Starlay Finance, a lending protocol running on Astar and Acala, was exploited on its Acala EVM deployment for about $2.1 million (SlowMist's figure). The attacker used a flaw in how the protocol's USDC pool calculated its liquidity index: a tiny deposit was credited as an enormous balance, which the attacker then used to borrow LDOT (or DOT) and withdraw far more than they had put in. Community discussion afterwards describes the DOT and LDOT deposits on Acala as lost.

In a February 9 incident report, Starlay said the USDC market had been listed at launch alongside DOT and LDOT but was never funded, so its index went un-updated for about 20 to 25 days. The team offered to treat the attacker as a whitehat, with no criminal proceedings, if the funds were returned. It also said it would work with centralized exchanges to trace the funds and restore Starlay on Astar and Acala without the USDC pool. In a February 20 forum proposal, community members concluded that legal action to unmask the attacker through exchanges would take months and cost several hundred thousand dollars, and put forward compensation or dissolution options instead.

How it happened

  1. Starlay's LendingPool updates reserve data on every user action, and the USDC reserve's liquidityIndex accrues with elapsed time. According to Starlay, the index started at 0 and the USDC pool held no funds for roughly 20 to 25 days.
  2. When the attacker deposited into the empty pool, the long gap in timestamps pushed liquidityIndex to about 1,350,009,778 × 10^27.
  3. lToken balances are computed as rayMul(realDeposit, liquidityIndex), so a deposit of 20 USDC (20,000,000 in 6 decimals) showed as an lToken balance of roughly 27,000,195,560,000,000,000 units.
  4. Using the inflated position as collateral, the attacker borrowed LDOT (or DOT) and withdrew USDC far beyond their real deposit, draining about $2.1 million from the Acala markets.

Protocol details

Classification Protocol Logic
Protocol Type Lending
Implementation language Solidity
Protocol links Website @starlay_fi

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.