logo

DFX Finance

ID: af4766e2-9e7c-532e-8350-9425b8c71d70

STIX ID: report--af4766e2-9e7c-532e-8350-9425b8c71d70

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2022-11-10

Date Updated: 2026-06-11

...
...

On 2022-11-10 DFX Finance's swapping contracts were exploited for roughly $5M when an attacker used flashloans to manipulate the contract's balance checks. By depositing flashloaned tokens during the loan callback, the attacker bypassed repayment verification, obtained LP tokens from deposit(), and then withdrew underlying CAD and USDC assets; transaction links and the attacker contract are provided. The vulnerability is a design flaw allowing flashloaned tokens to be used to 'repay' loans via deposit(), and the report recommends adding reentrancy-style guards; impacted protocols were paused at the time of writing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.