Vista Finance Hack
What happened
On October 22, 2024, Vista Finance, a protocol on Binance Smart Chain (BSC), suffered an exploit resulting in a loss of approximately $29,000.
The exploit originated from Vista Finance’s use of the flashLoan function, which mints tokens at the beginning of the process and burns them at the end. A critical vulnerability was found in the contract's _burn function, which directly adjusted the balance within _balances[account] rather than utilizing the getFreeBalance method. This discrepancy allowed the attacker to manipulate token balances, bypassing restrictions tied to staked tokens.
By initiating a flash loan for 1,000,000 tokens, the attacker was able to buy ICO tokens from Vista Finance using $1,500 in BUSD. These ICO tokens were then sold to another address for a profit. The exploit relied on the fact that getFreeBalance did not properly account for staked status, allowing the attacker to use the flash-minted tokens to bypass the staking limitations and cash out the gains undetected.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.solidityscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.