UEarnPool Hack
Reported loss
$16K
Reward Logic Flaw
What happened
On November 17, 2022, UEarnPool's BSC staking system was exploited through its invitation and team-reward design. CertiK reports that the attacker used a 2.4 million-USDT flash loan and 20 helper contracts configured as inviters to inflate reward-eligible stake share. The reported profit was 16,038 USDT.
How it happened
- The attacker configured helper contracts as inviters through the public bindInvitor function.
- They used a 2.4 million-USDT flash loan for repeated stake operations through those contracts.
- Each staking round distributed reward portions to inviter accounts and enabled another controlled inviter to start the next round.
- The helper contracts forwarded accumulated rewards to the attacker, who repaid the flash loan and retained the reported profit.
Protocol details
Classification
Protocol Logic
Protocol Type
DeFi Protocol
Implementation language
Solidity
Evidence
- analysis DeFiLlama defillama.com
- analysis Tokenomics In DeFi Staking certik.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.