logo

Paraluni Exploit

ID: d09b6573-c944-5cfa-8276-164dfbd718ac

STIX ID: report--d09b6573-c944-5cfa-8276-164dfbd718ac

Feed Name: CertiK Blog

Threat Score
72/100

Date Published: 2022-07-09

Date Updated: 2026-06-11

...
...

On March 13, 2022 Paraluni’s MasterChef contract was exploited via a reentrancy flaw combined with improper validation of the pool ID (_pid). The attacker deployed malicious ERC-20 tokens, used a flash loan to obtain LP tokens, triggered reentrant deposits to create duplicate accounting entries, withdrew assets, and converted/bridged proceeds (eventually depositing ~660 ETH to Tornado), resulting in about $1.7M stolen; the report provides technical analysis, relevant addresses/txs, and root-cause vulnerability details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.