Wault Finance Hack

TOTAL LOST $816K
Low Flash Loan Attacks bsc

What happened

Wault Finance's WUSD pegging mechanism on BNB Smart Chain was exploited on August 4, 2021. The team reported that the attacker gained about $816,000 from WUSDMaster, while independent analysis estimated roughly 370 ETH, or $800,000, extracted from the WUSD/BUSD pool. The incident was an economic design failure involving WUSD's WEX reserve component, not a theft of the isolated USDT collateral or treasury.

Technical Root Cause

WUSD's design automatically bought WEX on mint while allowing near-immediate WUSD redemption. With enough temporary liquidity, an attacker could force protocol-funded WEX purchases, raise WEX's market price, sell their own WEX into the move, and exit the WUSD position in the same transaction. Stablecoin reserve mechanisms must account for price impact and prevent atomic mint-pump-redeem cycles.

Case & protocol details

Classification Stablecoin Reserve / Economic Price Manipulation
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract WUSD, WEX
Official Website wault.finance/
Protocol Twitter/X @Wault_Finance

Attack Timeline

The attacker flash-borrowed WUSD and USDT, redeemed WUSD for USDT and WEX, and accumulated WEX. They repeatedly minted WUSD with USDT. Each mint automatically bought WEX, so the repeated mints pushed WEX higher while the attacker held a large WEX position.

The attacker sold WEX at the inflated price, sold the remaining WUSD through the WUSD/BUSD pool, repaid the flash loans, and retained the difference. Wault subsequently added one-block mint and redemption timelocks, a mint fee, and WEX sales on redemption.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.