Vee Finance Hack

TOTAL LOST $36.0M
High Flash Loan Attacks avalanche

What happened

A malicious smart contract was deployed to interact with one of the protocol smart contracts, leading to the withdrawal of funds.

The attacker deployed a smart contract with malicious logic that interacted with one of the protocol smart contracts. Both contracts are unverified. The funds were then withdrawn through a series of transactions.

The stolen WBTC and WETH were bridged to Ethereum and are still held on the attacker's address.

The attacker's address:

https://cchain.explorer.avax.network/address/0xeeeE458C…0595BA/transactions

The contract behind the attack:

https://cchain.explorer.avax.network/address/0x490D25A3…E70B82/transactions

The list of transactions where the funds were withdrawn:

https://cchain.explorer.avax.network/address/0x490D25A3…E70B82/token-transfers

The Ethereum address where the stolen WBTC and WETH are held:

https://etherscan.io/address/0xeeee458c…0595ba

Case & protocol details

Classification Ecosystem / Borrowing and Lending / Oracle Manipulation
Protocol Type Lending
Affected asset / contract VEE
Smart Contract Language Solidity
Official Website vee.finance/
Protocol Twitter/X @VeeFinance

Security review history

  • CertiK 2021-05-26 No public report
  • SlowMist 2021-09-08 No public report

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.