- Amount Lost: $1,401,772.00
- Funds Returned: $0.00
- Category: Yield Aggregator
- Date: 2021-2-8
The attacker's address:
https://etherscan.io/address/0x5e05bc89ae5f21b48500d9685526e0dab421a04b
The attacker created a fake token called AXZ and supplied rAXZZ/GRO liquidity. He then staked it in the contract and pulled out the other pair.
The attacker:
- swapped 0.001 WETH for ~0.0148 GRO:
https://etherscan.io/tx/0x97373e454e0d5bc7b552de8075c33ea257f570bea519dc2c6220658257b304b5
- added ~0.0148 GRO and 100,000,000,000 AXXZ into Uniswap liquidity pair:
https://etherscan.io/tx/0xa94c42b8d290369910e33c8e317bd996d8a774367fc2ba69b985a00a3dea6247
- removed ~27,516 GRO and ~1,218 rAAVE liquidity from Uniswap:
https://etherscan.io/tx/0x2152214a6be27a904af5a25e77fdca92ae60c6a9d7d298a41f88558649a41a23
- swapped ~27,516 GRO for ~597 WETH and ~1,218 rAAVE on ~203 WETH:
https://etherscan.io/tx/0xffef18b38096c96c1f6be784ea0ebb07964137858e38f3d65858a79e6a96797f
https://etherscan.io/tx/0xce020fabb3c56c75b23ac7d53d5259959a2b3ffe0b1a0d69aecaae9cd7757998
Stolen funds were distributed between 4 external wallets at:
https://etherscan.io/tx/0x0a6b5c92abcfbf07fb31d9e6c402b82c8756a80823c309d063a9a735d3f817eb
https://etherscan.io/tx/0xac4407bf2fa52003960449cecc92d3a9e0175f40d9bf11b9d808c3282f2ec2b4
https://etherscan.io/tx/0x0391fa91f18873566a31f5a6dd73b6ae5c4aa48146b64edf615eaacf0fece735
https://etherscan.io/tx/0xb80894d79ba238b1867ea17beb821f58084d42b52b7db24f04ca9cf1ae9b680c
Proof Links: