Wault Finance Hack
Incident Overview
The attacker:
https://bscscan.com/address/0x886358f9…410c64
The transaction behind the attack:
https://bscscan.com/tx/0x31262f15…e1670e
The attacker:
- flash loaned 16.8M WUSD from WSwap’s WUSD-USDT pool and redeemed it for 15M USDT and 106M WEX
- flash loaned 40M USDT from PCS’s WBNB-USDT pool
- swapped a part of the flash loaned USDT to WEX before the price is pumped
- staked the flash loaned USDT to WUSDMaster contract. The 10% of staked USDT was used to buy WEX and the attacker gained the WUSD with a 1:1 rate
- since there was a limit on the staking amount, the attacker performed the previous step repeatedly to increase the WEX price with almost no cost
- gained profit in USDT by swapping WEX from steps 1 and 3 back to USDT
- returned the flash loaned WUSD and USDT
- swapped the remaining WUSD and the USDT profit to ETH.
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Wault Finance, these are the critical security checks that could have prevented this incident (August 2021).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Wault Finance
The Wault Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.