Tsuru Hack
What happened
Tsuru, a Base memecoin launched for holders of the JOURNEY NFT collection, was exploited on May 10, 2024, about two hours after its contracts went live. The TSURUWrapper contract minted $TSURU whenever it received the project's ERC-1155 tokens through onERC1155Received, but anyone could call that callback directly. The attacker used it to mint 167.2 million TSURU without depositing anything and sold them into the TSURU/ETH Uniswap pool for about 137.8 ETH, roughly $410K at the time.
Tsuru's post-mortem says a last-minute code change converted a require guard into an if statement, so minting ran for a contract address the team had not intended to accept. SlowMist traced the attacker's funding to Tornado Cash, followed the proceeds to a consolidation wallet (0x5e209c84e8632c011b7b5209dda3f7e50409c446) and blocklisted the addresses. No funds were reported recovered. The team said it would relaunch as $NTSURU, seeding a new pool with about 225 ETH from buyback reserves and the remaining TSURU liquidity, and airdrop 400 NTSURU per JOURNEY NFT.
How it happened
- At launch,
TSURUWrapperminted TSURU to users who sent it JOURNEY NFTs or BRICK ERC-1155 tokens, with the mint running inside itsonERC1155Receivedhook. - The hook did not verify that
msg.senderwas the legitimate token contract or that any token had actually been transferred. The team attributes this to arequirecheck that was rewritten as anif. - The attacker (
0x7A5Eb99C993f4C075c222F9327AbC7426cFaE386), through attack contract0xa2209b48506c4e7f3a879ec1c1c2c4ee16c2c017, calledonERC1155Receiveddirectly with the project's token ID and a large amount, minting 167.2 million TSURU. - In the same transaction (
0xe63a8df8759f41937432cd34c590d85af61b3343cf438796c6ed2c8f5b906f62), the contract swapped the TSURU into the TSURU/WETH Uniswap V3 pool and took about 137.8 ETH.
Protocol details
Evidence
- report $TSURU Exploit Incident Report (Tsuru on Base GitBook, Wayback copy) base.tsuru.wtf
- report SlowMist Security Alert on X (2024-05-10 14:19 UTC, via fxtwitter mirror) x.com
- report shoucccc on X: 'Everyone can call this function to get free tokens' (2024-05-10, via fxtwitter mirror) x.com
- code DeFiHackLabs TSURU_exp.sol github.com
- analysis DeFiLlama defillama.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.