4 incidents · from rekt.news · post-mortems, no exploit code
Exploits
Four of the largest smart-contract incidents on rekt.news, as post-mortems: the contract that was attacked, the path the attack took, the check that was missing, and how an auditor catches it.
- 5 parties · 5 steps
Poly NetworkAug 10, 2021Access control: privileged targetEthCrossChainManager executes cross-chain messages by calling whatever contract a message names, and it owned EthCrossChainData, the contract holding the keepers' public keys. A message aimed at EthCrossChainData, with a method name chosen so its 4-byte selector matched putCurEpochConPubKeyBytes(bytes), replaced the keepers with the attacker's key; the attacker then signed withdrawals from LockProxy on three chains.EthCrossChainData.putCurEpochConPubKeyBytes·EthereumBSCPolygon$611M lost#4 on rekt.newsFunds returned - 4 parties · 8 steps
Euler FinanceMar 13, 2023Missing health checkEuler added donateToReserves (EIP-14) so users could give eTokens to the protocol's reserves. It lowered the donor's collateral but never ran the liquidity check every other balance-lowering function ends with, so an account could donate itself under water and be liquidated at the maximum discount by a second contract, which withdrew the collateral.EToken.donateToReserves·Ethereum$197M lost#17 on rekt.newsFunds returned - 4 parties · 6 steps
Nomad BridgeAug 1, 2022Unsafe initializationA June upgrade initialized Nomad's Replica with the zero hash as its committed root and marked it confirmed. A message that was never proven reads as root 0x00, so process() accepted any message: the first caller withdrew from the bridge, and hundreds of addresses copied the transaction with their own address in it.Replica.process·Ethereum$190M lost#19 on rekt.newsPartly returned - 5 parties · 8 steps
BeanstalkApr 17, 2022Governance: borrowed voting powerBeanstalk let a two-thirds supermajority execute a proposal at once through emergencyCommit, one day after it was proposed, and counted voting power (Stalk) from Silo deposits made in the same transaction. The attacker proposed BIP-18 a day early, then flash-borrowed enough to hold about 70% of Stalk, voted, and executed a proposal that sent the protocol's assets to them, all in one transaction.GovernanceFacet.emergencyCommit·Ethereum$181M lost#20 on rekt.newsNot recovered
Historical and closed. Each step follows the public post-mortems linked in its case; the code is illustrative, simplified to the pattern. Key thefts and off-chain failures on the leaderboard (Ronin, Bybit, BNB Bridge) were not smart-contract bugs and are not here.
BSC
Polygon