SteamSwap Hack

Reported loss $105K
BNB Chain
Spot Price Manipulation

What happened

Steam Swap, a BNB Chain trading platform, lost about $105,000 on June 6, 2024 when two attackers exploited its MineSTM contract. The contract's sell function priced STM redemptions from the live reserves of the BSC-USD/STM PancakeSwap pair, so a large swap in the same transaction changed how much liquidity it paid out. The first attacker, using a 500,000 BSC-USD flash loan, took about $91,670.

A second attacker, likely a copycat, repeated the trick for about $13,892. Neptune Mutual noted that the contract had been deployed about 16 hours before the attack and had not been audited, and it raised the possibility of an inside job; that suspicion is unproven. The team said it would commission an audit after the incident.

How it happened

  1. The attacker flash-borrowed 500,000 BSC-USD from a PancakeSwap V3 pool.
  2. It swapped the borrowed BSC-USD for about 2.74 million STM in the BSC-USD/STM pair, which skewed the pair's reserves.
  3. It called updateAllowance() on MineSTM, approved STM, and called sell() several times. Each call computed lpAmount = amount * totalSupply / (2 * r1) from the manipulated reserve r1 and removed that much LP liquidity to the caller, returning more BSC-USD and STM than the tokens were worth.
  4. The attacker sold the extra STM, repaid the flash loan plus fee, and kept about $91,670. A second address later ran the same sequence for about $13,892.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.