Whale Loans Hack

TOTAL LOST $12K
Low Other

What happened

Whale Loans was exploited due to K-check of the WhaleSwap Finance Pair contract. When a user swaps, there is an issue with the magnitude of the parameters passed in.

The attacker flashloaned BSC-USD and then returns flashloan with a K-check parameter in function swap() contract WhaleswapPair.sol of magnitude 10000^4. However, the K-check takes a parameter of magnitude 10000^2, which causes the K-check to fail.

Exploiter address: https://bscscan.com/address/0xd793ff8d…bf7a50

Attack transaction: https://bscscan.com/tx/0x9f5b02cb…0ebab3

Attacker contract: https://bscscan.com/address/0xf9553675…29385f

Victim address: https://bscscan.com/address/0x8bfee2ca…e76794

Case & protocol details

Classification Borrowing and Lending
Protocol Type Reserve Currency
Affected asset / contract HUMP
Official Website whale.loans/dashboard
Protocol Twitter/X @WhaleLoans

Security review history

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.