UEarnPool Hack

Reported loss $16K
BNB Chain
Reward Logic Flaw

What happened

On November 17, 2022, UEarnPool's BSC staking system was exploited through its invitation and team-reward design. CertiK reports that the attacker used a 2.4 million-USDT flash loan and 20 helper contracts configured as inviters to inflate reward-eligible stake share. The reported profit was 16,038 USDT.

How it happened

  1. The attacker configured helper contracts as inviters through the public bindInvitor function.
  2. They used a 2.4 million-USDT flash loan for repeated stake operations through those contracts.
  3. Each staking round distributed reward portions to inviter accounts and enabled another controlled inviter to start the next round.
  4. The helper contracts forwarded accumulated rewards to the attacker, who repaid the flash loan and retained the reported profit.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.