THORChain DEX Hack

Reported loss $350K
Ethereum
Bridge Logic Flaw

What happened

On 28 June 2021 (UTC), an attacker exploited a logic bug in THORChain's Ethereum Bifrost, the component that watches ETH and ERC-20 deposits into THORChain vaults. The attacker made a custom ERC-20 token whose symbol was "ETH". The Bifrost recorded deposits of that token as native ETH (ETH.ETH), and the attacker swapped the fake ETH for real assets from THORChain's pools.

THORChain's post-mortem lists 9,352.49 PERP, 1.44 YFI, 2,437.94 SUSHI and 10.615 ETH taken, about $139,000 at the time. SlowMist's later MistTrack analysis found more losses that the official count had missed (29,777 USDT, 78.14 ALCX, 11.75 ETH and 0.60 YFI) and puts the total at nearly $350,000. Users reported the unusual transactions, and nodes halted the network about 20 minutes later.

A fix was written within about two hours, and swaps resumed about six hours after the report. THORChain said its treasury would restore vault solvency. According to SlowMist, the attacker had prepared from 21 June with funds from ChangeNOW, deployed the attack contract on 26 June, and later sent ETH proceeds to Tornado Cash.

This was the first of three THORChain exploits in the summer of 2021.

How it happened

  1. The attacker funded wallets through ChangeNOW and deployed an attack contract and an ERC-20 token whose symbol() returned "ETH".
  2. The Ethereum Bifrost set every observed asset to common.ETHAsset by default. It was supposed to replace that with ETH.SYMBOL-0xADDRESS for ERC-20s, but it skipped that step when the token's symbol was "ETH".
  3. Deposits of the fake token were therefore credited to THORChain as real ETH.ETH. The first exploit tx, 0x966cb083d116da2e0d1d115a99381db2200bd39ff75d38cfacdc17b1368f1159, sent 0 real ETH.
  4. In five swaps, the attacker traded about 62 fake ETH for PERP, SUSHI and YFI from THORChain's pools. One more swap sent after trading was halted was refunded in real ETH.
  5. Nodes halted the chain, merged a fix that starts assets as common.EmptyAsset, added logic to ignore the attacker's pending transactions, and resumed swaps.

Protocol details

Classification Bridge & Cross-Chain
Protocol Type DEX
Category Bridge Hack
Implementation language Go
Protocol links Website @THORChain

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.