Starlay Finance Hack
What happened
On February 8, 2024, Starlay Finance, a lending protocol running on Astar and Acala, was exploited on its Acala EVM deployment for about $2.1 million (SlowMist's figure). The attacker used a flaw in how the protocol's USDC pool calculated its liquidity index: a tiny deposit was credited as an enormous balance, which the attacker then used to borrow LDOT (or DOT) and withdraw far more than they had put in. Community discussion afterwards describes the DOT and LDOT deposits on Acala as lost.
In a February 9 incident report, Starlay said the USDC market had been listed at launch alongside DOT and LDOT but was never funded, so its index went un-updated for about 20 to 25 days. The team offered to treat the attacker as a whitehat, with no criminal proceedings, if the funds were returned. It also said it would work with centralized exchanges to trace the funds and restore Starlay on Astar and Acala without the USDC pool. In a February 20 forum proposal, community members concluded that legal action to unmask the attacker through exchanges would take months and cost several hundred thousand dollars, and put forward compensation or dissolution options instead.
How it happened
- Starlay's
LendingPoolupdates reserve data on every user action, and the USDC reserve'sliquidityIndexaccrues with elapsed time. According to Starlay, the index started at 0 and the USDC pool held no funds for roughly 20 to 25 days. - When the attacker deposited into the empty pool, the long gap in timestamps pushed
liquidityIndexto about 1,350,009,778 × 10^27. - lToken balances are computed as
rayMul(realDeposit, liquidityIndex), so a deposit of 20 USDC (20,000,000 in 6 decimals) showed as an lToken balance of roughly 27,000,195,560,000,000,000 units. - Using the inflated position as collateral, the attacker borrowed LDOT (or DOT) and withdrew USDC far beyond their real deposit, draining about $2.1 million from the Acala markets.
Protocol details
Evidence
- report Starlay Finance on X: Security Incident Report: Anomaly in USDC Pool and Exploitation x.com
- analysis DeFiLlama defillama.com
- analysis SlowMist Hacked - Polkadot category (Starlay Finance entry) hacked.slowmist.io
- analysis Starlay Finance USDC Pool Compromised, Invites Hacker To Negotiate blockchainreporter.net
- analysis Strategic reevaluation of legal actions post-security breach and proposal for forward path forum.starlay.finance
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.