Cryptocurrency [loss] $2M+

Tweet thread by CertiK Alert

2023-11-07 [vendor] MEV bot 0x05f01 [chain] ethereum, bitcoin
Primary Source ↗
Financial Loss $2.0M (1,975,448 USD)
Blockchain(s) Ethereum, Bitcoin

Incident Details

An MEV bot was exploited after an attacker discovered a vulnerability in its code that allowed anyone to call one of its functions that sold wBTC for wETH. Using a flash loan to imbalance a wETH/wBTC pool on Curve, the attacker then caused the bot to purchase wBTC at its inflated price. They then sold the wBTC for a profit. Altogether, the exploiter made off with 1,047 ETH ($1.975 million).

Total loss estimated at $1,975,448.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
MEV bot 0x05f01

Timeline

  1. 2023-11-07 Breach occurred
  2. 2023-11-07 Publicly disclosed