CryptoReal
CASE FILE — Jan 31, 2024

Rounding Error in CauldronV4 Lets Attacker Drain $6.5M and Briefly Depeg MIM

On January 30, 2024, two of Abracadabra's lending vaults ("cauldrons") were exploited, resulting in a loss of roughly $6.5 million on Ethereum and a temporary depegging of the protocol's stablecoin, Magic Internet Money (MIM).

Security firms BlockSec and Peckshield flagged the incident as it unfolded, with BlockSec urging users to withdraw funds from the affected contracts. Abracadabra confirmed the exploit shortly afterward and said its DAO treasury would attempt to restore MIM's peg:

To the best of its Ability, the DAO treasury will be buying back MIM from the market to then burn.

According to an Abra team member, the situation was contained roughly one hour after the attack started, and the team's buyback efforts pushed MIM back up to about $0.95. As of the time of writing, the token was trading near $0.97, still short of a full recovery.

Post-incident analysis credited to Offside Labs, EXVULSEC, and Kankodu traced the root cause to a rounding bug in the CauldronV4 contract code, matching what researchers had first suspected in the immediate aftermath.

Specifically, the borrow function in CauldronV4 mismanaged the "part" parameter — the accounting figure representing a user's share of total debt. By repeatedly borrowing and repaying, an attacker could manipulate this rounding error to distort the debt calculation. A deeper technical breakdown is available here. Exploiting the flaw let the attacker siphon MIM liquidity out of the yvCrv3Crypto and magicAPE cauldrons.

Researchers at EXVULSEC outlined the attack sequence as follows:

Sums referenced in this case file
  1. Flashloan MIM tokens via Degenbox.
  2. Donate MIM to BentoBox by depositing it with BentoBox itself listed as the recipient — exploiting the ERC-4626 "first depositor" attack vector.
  3. Call repayForAll() to clear other users' liabilities. Since this alone doesn't fully zero out the elastic debt value (it needs to fall below a 1000 * 1e18 threshold), the attacker manually repays additional borrower debt to bring it to zero.
  4. Repeatedly borrow and repay to artificially inflate the share price — the well-documented ERC-4626 vault share inflation exploit.
  5. Deposit collateral and borrow a large sum of MIM.
  6. Repay the flashloan and pocket the difference as profit.

The attacker's subsequent dumping of the stolen MIM for ETH is what triggered the stablecoin's price to slip from its dollar peg.

The exploiter's wallet has been identified as 0x87f585809ce79ae39a5fa0c7c96d0d159eb678c9. Two attack transactions were recorded: the first at 10:14 UTC (0x26a83db7…) and the second at 10:26 UTC (0xdb4616b8…).

The two exploited CauldronV4 contracts were yvCrv3Crypto (0x7259e152103756e1616A77Ae982353c3751A6a90) and magicAPE (0x692887E8877C6Dd31593cda44c382DB5b289B684).

The stolen funds are currently split between two addresses: one holding approximately $4.2 million (Exploiter address 2) and another holding approximately $2.2 million (Exploiter address 3). Abracadabra's team has since sent on-chain messages (tx 1, tx 2) to the attacker in an effort to open negotiations.

The exploit lands in a month already marked by other incidents at Gamma Strategies and Radiant Capital, plus the widely mocked false-alarm ETF approval announcement. Despite the scale of the loss, market reaction to the Abracadabra hack was relatively muted compared to prior cycles.

Abracadabra's Degenbox product played a central role in the excessive leverage strategies tied to Anchor Protocol that contributed to the collapse of LUNA/UST in 2021. Co-founder Daniele Sesta remains one of the few prominent figures from that era who has avoided criminal prosecution. The "Frog Nation" family of projects he backed grew to substantial total value locked in 2021 largely on marketing momentum and a populist "Occupy DeFi" framing rather than novel technology — a pattern that continued even after Popsicle Finance lost $20 million and Wonderland was rocked by the Sifu scandal.

Notably, this exploit occurred shortly after Sesta had teased new project offerings, raising questions about what else may be in store.

AbracadabraMIM
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.