Wild Credit Hack

REPORTED LOSS $612K
Low Access Control

What happened

The attacker's address:

https://etherscan.io/address/0xb1af124c…cdb95e

The transaction behind the attack:

https://etherscan.io/tx/0xdbef3b39…42ce07

The exploited contract:

https://etherscan.io/address/0x7b3b69ea…cdc6ca

Wild Credit team left initialize() function in the LPTokenMaster contract public and reusable, so anyone can become the owner of the LP token contract. The hacker took ownership of the contract, has minted tokens to themselves, and then used those tokens to withdraw real funds.

The hacker was a whitehat and returned the funds to the contract deployer:

https://etherscan.io/tx/0xb4fffa0e…434542

Case & protocol details

Classification Borrowing and Lending
Protocol Type Lending
Affected asset / contract WILD
Official Website wild.credit/
Protocol Twitter/X @WildCredit

Security review history

Funds Recovery

100.0%

Recovered

$612K

Net Loss

$0

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.