Tsuru Hack

Reported loss $410K
Base
Unknown

What happened

Tsuru, a Base memecoin launched for holders of the JOURNEY NFT collection, was exploited on May 10, 2024, about two hours after its contracts went live. The TSURUWrapper contract minted $TSURU whenever it received the project's ERC-1155 tokens through onERC1155Received, but anyone could call that callback directly. The attacker used it to mint 167.2 million TSURU without depositing anything and sold them into the TSURU/ETH Uniswap pool for about 137.8 ETH, roughly $410K at the time.

Tsuru's post-mortem says a last-minute code change converted a require guard into an if statement, so minting ran for a contract address the team had not intended to accept. SlowMist traced the attacker's funding to Tornado Cash, followed the proceeds to a consolidation wallet (0x5e209c84e8632c011b7b5209dda3f7e50409c446) and blocklisted the addresses. No funds were reported recovered. The team said it would relaunch as $NTSURU, seeding a new pool with about 225 ETH from buyback reserves and the remaining TSURU liquidity, and airdrop 400 NTSURU per JOURNEY NFT.

How it happened

  1. At launch, TSURUWrapper minted TSURU to users who sent it JOURNEY NFTs or BRICK ERC-1155 tokens, with the mint running inside its onERC1155Received hook.
  2. The hook did not verify that msg.sender was the legitimate token contract or that any token had actually been transferred. The team attributes this to a require check that was rewritten as an if.
  3. The attacker (0x7A5Eb99C993f4C075c222F9327AbC7426cFaE386), through attack contract 0xa2209b48506c4e7f3a879ec1c1c2c4ee16c2c017, called onERC1155Received directly with the project's token ID and a large amount, minting 167.2 million TSURU.
  4. In the same transaction (0xe63a8df8759f41937432cd34c590d85af61b3343cf438796c6ed2c8f5b906f62), the contract swapped the TSURU into the TSURU/WETH Uniswap V3 pool and took about 137.8 ETH.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.