uniclyNFT Hack

Reported loss $2K
Ethereum
Reentrancy

What happened

On September 16, 2023, an attacker used reentrancy in Unicly's PointFarm contract on Ethereum to mint unearned reward points. The attacker spent the points on a LootRealms (Realm) NFT, ID 4689, from Unicly's PointShop. PointFarm pays rewards as ERC-1155 points, and minting them triggers the onERC1155Received callback on the recipient.

According to Olympix, the farm updated the depositor's rewardDebt only after this external call. Re-entering deposit() from the callback therefore paid the same pending rewards again. Olympix put the loss at about $2,000.

Decurity reported that the attacker was funded through FixedFloat. No Unicly statement or recovery was found.

How it happened

  1. About two days before the attack, the attacker swapped WETH for uJENNY and deposited about 3,528 uJENNY into PointFarm pool 0 to start earning points.
  2. In attack tx 0xc42fe1ce2516e125a386d198703b2422aa0190b25ef6a7b0a1d3c6f5d199ffad, the attacker contract called deposit(0, 0) to claim its pending points.
  3. PointFarm minted the points as ERC-1155 tokens, which called back into the attacker's onERC1155Received. The callback called deposit(0, 0) again before rewardDebt was updated, and repeated until the point balance passed the NFT price.
  4. The attacker withdrew the original uJENNY deposit and swapped it back to WETH.
  5. It approved PointShop, redeemed the inflated points for Realm NFT #4689, and then listed the NFT for sale.

Protocol details

Classification Reentrancy
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.