UtopiaSphere Hack

Reported loss $521K
BNB Chain
Spot Price Manipulation

What happened

On July 21, 2024, the UtopiaSphere UPS token on BNB Smart Chain was exploited for about $521,000. UPS had a _swapBurn() mechanism that burned part of the tokens sent to its designated trading pair when users sold. The attacker used flash loans to buy up most of the UPS in the UPS/USDT pair, then triggered the burn so that only 1 wei of UPS was left in the pair, and bought out almost all the USDT with a small amount of UPS.

After repaying the flash loans, the exploiter swapped the profit to 147.6 ETH and bridged it to Ethereum address 0x2Eb88341BE58a04E6e7daCB32d01Ae2450dCC257. The UPS/USDT pair has stayed empty since. It was UtopiaSphere's second exploit of 2024: the same flaw was used on April 8, 2024 for about $28K. No public response or compensation from the project has been found.

How it happened

  1. The exploiter (0x6e12ce089a8BedeA49532010229f0913475d8d9c) recursively borrowed 89.672M USDT through flash loans, then minted 7.917M vUSDC to borrow another 6.424M USDT.
  2. The 96.196M USDT was swapped for 810.833M UPS, taking most of the pair's UPS.
  3. The exploiter then sold 4.982M UPS. As the tokens were transferred to the pair, _swapBurn() burned 95% of the amount from the pair, leaving exactly 1 wei of UPS in its reserves.
  4. With the reserve ratio broken, the exploiter swapped 4.733M UPS for all 96.756M USDT (BSC-USD) in the pair.
  5. The flash loans were repaid, leaving about $521K profit. Attack transaction: 0x1ddf415a4b18d25e87459ad1416077fe7398d5504171d4ca36e757b1a889f604.

Protocol details

Classification Oracle Manipulation
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.