Wault Finance Hack
What happened
Wault Finance's WUSD pegging mechanism on BNB Smart Chain was exploited on August 4, 2021. The team reported that the attacker gained about $816,000 from WUSDMaster, while independent analysis estimated roughly 370 ETH, or $800,000, extracted from the WUSD/BUSD pool. The incident was an economic design failure involving WUSD's WEX reserve component, not a theft of the isolated USDT collateral or treasury.
WUSD's design automatically bought WEX on mint while allowing near-immediate WUSD redemption. With enough temporary liquidity, an attacker could force protocol-funded WEX purchases, raise WEX's market price, sell their own WEX into the move, and exit the WUSD position in the same transaction. Stablecoin reserve mechanisms must account for price impact and prevent atomic mint-pump-redeem cycles.
Case & protocol details
Attack Timeline
The attacker flash-borrowed WUSD and USDT, redeemed WUSD for USDT and WEX, and accumulated WEX. They repeatedly minted WUSD with USDT. Each mint automatically bought WEX, so the repeated mints pushed WEX higher while the attacker held a large WEX position.
The attacker sold WEX at the inflated price, sold the remaining WUSD through the WUSD/BUSD pool, repaid the flash loans, and retained the difference. Wault subsequently added one-block mint and redemption timelocks, a mint fee, and WEX sales on redemption.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report watchpug.medium.com
- report Report inspexco.medium.com
- transaction Transaction bscscan.com
- analysis Wault Finance WUSD incident recap waultfinance.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.