WIFCOIN Hack

Reported loss Not disclosed
Ethereum
Unknown

What happened

In June 2024, an attacker drained the WIF token rewards held by the WIFCOIN staking contract on Ethereum. WIFStaking.claimEarned() paid a flat reward of amount * apr / 10000 on every call. It did not check whether the stake had matured or how much time had passed since the last claim.

It also did not reset the reward: the function updated stakeAt, but the payout calculation never read it. After staking in plan 3, the 6% plan, the attacker could call claimEarned() over and over in one transaction until the contract ran out of WIF. DeFiHackLabs puts the attacker's profit at about 3.4 ETH; ChainAegis estimated the loss at about $14K.

No project response was found.

How it happened

  1. The attacker swapped about 0.3 ETH for WIF on Uniswap V2.
  2. It staked the WIF in WIFStaking plan 3 (stake(3, amount)), which pays 6% (apr = 600).
  3. In a loop, it called claimEarned(3, 10), choosing the lowest 10% burn rate. Each call paid 6% of the stake, less the burn, with no maturity or elapsed-time check.
  4. The loop ran until a call reverted because the staking contract no longer held enough WIF.
  5. The attacker sold the collected WIF back to ETH on Uniswap V2. The attack ran over two transactions, 0xda8f6a4b...e284 and 0x58424115...9e09.

Protocol details

Classification Protocol Logic
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.