WOOFi Swap Hack

TOTAL LOST $8.8M
Medium Flash Loan Attacks Arbitrum

What happened

On March 5, 2024, an attacker exploited WOOFi Swap's synthetic proactive market maker on Arbitrum. Flash-borrowed WOO and low available liquidity let the attacker force WOOFi's internal WOO price close to zero, acquire WOO at a negligible cost, and extract value through three rapid attack cycles.

Technical Root Cause

WOOFi's sPMM price calculation could push WOO's internal price far outside its intended range under a large trade. The fallback validation that would compare against Chainlink did not cover WOO, so the implausible price was accepted instead of reverting.

Case & protocol details

Classification Oracle Manipulation / AMM Price Calculation
Protocol Type DEX
Smart Contract Language Solidity
Official Website x.woo.org/
Protocol Twitter/X @_WOOFi

Attack Timeline

The attacker borrowed WOO and other assets through flash-loan arrangements, sold WOO into WOOFi, and triggered an extreme internal WOO price adjustment. With the manipulated price near zero, the attacker swapped out roughly 10 million WOO for almost no cost, unwound the position, and repaid the loans. Repeating the sequence three times produced about $8.75 million in net profit after flash-loan repayment.

The affected sPMM pricing path normally uses oracle validation as a fallback. WOO was not covered by that Chainlink fallback, so the implausible internal price was accepted instead of reverting. WOOFi paused the Arbitrum Swap contracts shortly after detection; its other product contracts were unaffected.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.