WiseLending Hack

Reported loss $260K
Ethereum
Rounding Error

What happened

On 13 October 2023 Wise Lending's pools on Ethereum were drained of about $260,000 through a share-price inflation and rounding bug in a newly created WBTC pool. The transaction came from the MEV bot of c0ffeebabe.eth, a known whitehat that front-ran the pending attack and so got the funds before the original attacker could. BlockSec said the attack combined two issues: a direct donation of tokens that pushed up the value of each share, and a rounding error that let the attacker withdraw the donated WBTC while burning zero shares.

The bad WBTC collateral value let the transaction borrow out the reserves of nine other pools, including wstETH, WETH, DAI, sDAI, USDC and several Aave-wrapped tokens. Those loans were never repaid.

How it happened

  1. The transaction flash-borrowed 50 WBTC from Balancer.
  2. It opened two positions in the empty WBTC pool and deposited 1 wei of WBTC into each, getting one share per position.
  3. It sent about 49.99999998 WBTC straight to the contract. The pool's syncPool clean-up counted the surplus balance into pseudoTotalPool, so 3 shares were now valued at about 50 WBTC, roughly 16.67 WBTC per share.
  4. Using that inflated collateral value, it borrowed the entire reserves of nine other Wise Lending pools.
  5. It took the donated WBTC back with repeated withdrawExactAmount calls. Each call computed withdrawShares = amount * totalShares / pseudoTotalPool, which rounded down to 0, so real WBTC came out and no shares were burned.
  6. It repaid the flash loan, topping up a small WBTC shortfall with a Uniswap swap, and kept the borrowed assets (tx 0x7ac4a98599596adbf12fffa2bd23e2a2d2ac7e8989b6ea043fcc412a29126555).

Protocol details

Classification Token & Share Accounting
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.