header banner

The second flash loan attack against the DeFi protocol Platypus in nine months

Table of Contents

    Platypus, the Avalanche-native StableSwap protocol, suspended all of its pools on Thursday after detecting a flash loan exploit on the DeFi platform.

    PeckShield, the first to report on the platform attack, disclosed on Thursday that the exploit led to losses exceeding $2 million.

    Blockchain security firm CertiK laid out the results of its own investigation, saying that two attackers had taken about $1.3 million worth of wrapped AVAX (WAVAX) and about $913,000 in liquid staked AVAX (sAVAX).

    Playtypus is currently investigating what went down.

    Loading Tweet..

    “The whole team is working & communicating with different parties to try to recover the funds from the contracts, identify the root cause of this exploit, and trace the identity of the hacker(s) right now. We will share the updates with the community soon,” a moderator wrote on the protocol’s Discord channel on Thursday.

    Platypus is an automated market maker (AMM) protocol within the Avalanche blockchain, created with the primary goal of exchanging stablecoins.

    The protocol raised $3.3 million in Dec. 2021 in a funding round led by now defunct crypto hedge fund Three Arrows Capital (3AC) and Defiance Capital.

    The protocol suffered a separate exploit in February, losing more than $8.5 million. 

    That incident was also a flash loan attack — where traders can instantaneously borrow cryptocurrencies without providing collateral and return them within the same transaction.

    In that particular attack, the perpetrators exploited a vulnerability in Platypus’ native stabletoken’s USP solvency check mechanism, deceiving its smart contracts into believing that USP was completely backed.

    As of September, the Platypus team recovered about 61.7% of the original losses incurred by its liquidity pools during the USP exploit. 

    They tapped into a reserved treasury to initiate a second phase of compensation on Sept. 26, the team said on X.

    Platypus said it would share additional updates on the latest exploit in time.

    Don’t miss the next big story – join our free daily newsletter.

    Follow Sam Bankman-Fried’s trial with the latest news from the courtroom. 

    • Avalanche
    • exploit
    • Flash Loans


    Article information

    Author: Seth Howard

    Last Updated: 1697988361

    Views: 1194

    Rating: 3.7 / 5 (46 voted)

    Reviews: 82% of readers found this page helpful

    Author information

    Name: Seth Howard

    Birthday: 1919-01-13

    Address: 592 Drake Ferry, Wagnerland, NM 22821

    Phone: +3599980274136920

    Job: Human Resources Manager

    Hobby: Gardening, Telescope Building, Photography, Archery, Kite Flying, Lock Picking, Meditation

    Introduction: My name is Seth Howard, I am a persistent, honest, audacious, vibrant, Determined, important, spirited person who loves writing and wants to share my knowledge and understanding with you.