Hackerdao Incident Analysis
ID: 649658e7-4df5-59e4-8439-3f47594be4e7
STIX ID: report--649658e7-4df5-59e4-8439-3f47594be4e7
Feed Name: CertiK Blog
On May 24, 2022 an attacker executed a flash-loan-based exploit against the Hackerdao token on BSC, abusing the token's special extra-fee behavior for transfers to a specific liquidity pool and the UniswapV2Pair "skim" mechanism to manipulate multiple pools and drain roughly 200 BNB (~$65K). The attacker took a DODO flashloan, performed swaps to alter pool balances, used skim calls to move tokens between pools which triggered extra fees, then swapped inflated tokens back to WBNB, repaid the loan and sent proceeds to Tornado Cash; several transaction and contract addresses are included. The report concludes the vulnerability could have been avoided with contract auditing and notes reduced project activity post-attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
