Cryptocurrency [loss] $971,248

Tweet by MevRefund

2022-10-14 [vendor] Earning.Farm attack [chain] ethereum
Primary Source ↗
Financial Loss $971,248 (971,248 USD)
Blockchain(s) Ethereum

Incident Details

The defi project Earning.Farm lost 748 ETH ($971,000) to a hacker using a flash loan attack. The project contract was missing a check that a flash loan was initiated by the protocol, so the attacker was able to instruct the project to withdraw large amounts of funds, which they then were able to transfer to themselves.Amusingly, one of the transactions by the hacker was frontrun by a MEV bot known as 0xa57, which made a tidy 480 ETH ($623,000) from the attack. The second transaction succeeded, landing the attacker 268 ETH (~$348,000). According to a MEV researcher, 0xa57 has been known to return funds that were obtained as a result of a hack.

Total loss estimated at $971,248.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
Earning.Farm attack

Timeline

  1. 2022-10-14 Breach occurred
  2. 2022-10-14 Publicly disclosed