uniclyNFT Hack
What happened
On September 16, 2023, an attacker used reentrancy in Unicly's PointFarm contract on Ethereum to mint unearned reward points. The attacker spent the points on a LootRealms (Realm) NFT, ID 4689, from Unicly's PointShop. PointFarm pays rewards as ERC-1155 points, and minting them triggers the onERC1155Received callback on the recipient.
According to Olympix, the farm updated the depositor's rewardDebt only after this external call. Re-entering deposit() from the callback therefore paid the same pending rewards again. Olympix put the loss at about $2,000.
Decurity reported that the attacker was funded through FixedFloat. No Unicly statement or recovery was found.
How it happened
- About two days before the attack, the attacker swapped WETH for uJENNY and deposited about 3,528 uJENNY into PointFarm pool 0 to start earning points.
- In attack tx
0xc42fe1ce2516e125a386d198703b2422aa0190b25ef6a7b0a1d3c6f5d199ffad, the attacker contract calleddeposit(0, 0)to claim its pending points. - PointFarm minted the points as ERC-1155 tokens, which called back into the attacker's
onERC1155Received. The callback calleddeposit(0, 0)again beforerewardDebtwas updated, and repeated until the point balance passed the NFT price. - The attacker withdrew the original uJENNY deposit and swapped it back to WETH.
- It approved PointShop, redeemed the inflated points for Realm NFT #4689, and then listed the NFT for sale.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs uniclyNFT_exp.sol raw.githubusercontent.com
- analysis Decurity alert on uniclyNFT PointFarm (X, via fxtwitter mirror) api.fxtwitter.com
- analysis Compromised Private Keys Cost Fantom Foundation $7M (Olympix weekly roundup, uniclyNFT section) olympix.substack.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.