Cryptocurrency [loss] $9M+

Woofi

2024-03-05 [vendor] WOOFi [chain] ethereum
Primary Source ↗
Financial Loss $8.8M (8,750,000 USD)
Blockchain(s) Ethereum

Incident Details

An attacker was able to use a flash loan attack to manipulate an oracle on the WooFi DEX implementation on the Arbitrum network. By manipulating the price of $WOO, they were able to steal around $8.5 million.Blockchain security firms detected the attack quickly, and the project team paused the project’s smart contract within fifteen minutes, but not before the millions were stolen. They contacted the attacker via an on-chain message to offer a 10% “bounty”, later threatening that they had a “strong lead that we think will soon reveal the identity of the exploiter”.

Total loss estimated at $8,750,000.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
WOOFi

Timeline

  1. 2024-03-05 Breach occurred
  2. 2024-03-05 Publicly disclosed