WIFCOIN Hack
What happened
In June 2024, an attacker drained the WIF token rewards held by the WIFCOIN staking contract on Ethereum. WIFStaking.claimEarned() paid a flat reward of amount * apr / 10000 on every call. It did not check whether the stake had matured or how much time had passed since the last claim.
It also did not reset the reward: the function updated stakeAt, but the payout calculation never read it. After staking in plan 3, the 6% plan, the attacker could call claimEarned() over and over in one transaction until the contract ran out of WIF. DeFiHackLabs puts the attacker's profit at about 3.4 ETH; ChainAegis estimated the loss at about $14K.
No project response was found.
How it happened
- The attacker swapped about 0.3 ETH for WIF on Uniswap V2.
- It staked the WIF in
WIFStakingplan 3 (stake(3, amount)), which pays 6% (apr = 600). - In a loop, it called
claimEarned(3, 10), choosing the lowest 10% burn rate. Each call paid 6% of the stake, less the burn, with no maturity or elapsed-time check. - The loop ran until a call reverted because the staking contract no longer held enough WIF.
- The attacker sold the collected WIF back to ETH on Uniswap V2. The attack ran over two transactions,
0xda8f6a4b...e284and0x58424115...9e09.
Protocol details
Evidence
- address Etherscan verified source: WIFStaking 0xA1cE40702E15d0417a6c74D0bAB96772F36F4E99 etherscan.io
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs WIFCOIN_ETH_exp.sol raw.githubusercontent.com
- analysis ChainAegis alert on WIFCOIN_ETH (X, via fxtwitter mirror) api.fxtwitter.com
- analysis DeFiHackLabs README 2024 entry '20240616 WIFCOIN_ETH - business logic flaw' raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.