CryptoReal
CASE FILE — Aug 15, 2022

Misconfigured Liquidity Pool Lets Acala Users Mint $1.3 Billion in Excess aUSD

A configuration error in a newly launched liquidity pool on Acala Network, the Polkadot-based project describing itself as the "DeFi Hub of Polkadot," allowed users to mint roughly $1.3 billion worth of the protocol's aUSD stablecoin without proper backing.

Acala disabled token transfers shortly after the incident was discovered, pending a governance vote to resolve the situation, which limited the amount attackers could move off-chain despite the scale of the erroneous minting. The aUSD price chart showed the depeg pattern typical of stablecoin incidents of this kind.

How the misconfiguration occurred

According to Acala's own statement, the issue stemmed from a misconfiguration in the iBTC/aUSD liquidity pool, which had gone live earlier the same day. The error caused the pool's incentives.claim_rewards() extrinsic to mint aUSD in exponential quantities. The pool had just finished its bootstrapping phase and was incentivized with aUSD, ACA, and INTR rewards when the flaw was triggered.

Acala said: "We have identified the issue as a misconfiguration of the iBTC/aUSD liquidity pool (which went live earlier today) that resulted in error mints of a significant amount of aUSD," adding that "the misconfiguration has since been rectified and wallet addresses that received the erroneously minted aUSD have been identified, with on-chain activity tracing in respect of these addresses underway."

Distribution of the erroneous mint

Most of the erroneously minted supply, roughly 1.2 billion aUSD, ended up with a single user. Separately, a handful of other participants extracted value from the malfunction through three routes: transferring aUSD to Moonbeam, swapping it for DOT and moving the DOT to Polkadot, and swapping it for iBTC and moving that to Interlay.

Sums referenced in this case file

The iBTC pool was nearly fully drained as a result. The DOT pool retained more of its value because it was structured as a DOT-LCDOT pool, and the extra step required to route funds through it limited the damage.

Two wallet addresses were identified as having profited the most:

  • 23bmUgSeKMD8Y9triphPw5YHuiz3QUJNqcbmb3Eg9QMQDMWN
  • 253pFTg22JqHbLeLZupexGMDUuXAJLfEriTYkFqvGWPuwcFi

A number of other users also extracted value from the misconfiguration, though it is unclear whether all of them acted with intent to exploit the bug. In total, approximately $1.6 million in value was transferred off-chain by users, alongside $4.6 million in erroneously minted aUSD that also left the chain as bad debt.

Because Acala and the underlying Polkadot infrastructure were able to disable transfers relatively quickly, the scope of permanently lost funds was constrained despite the size of the initial erroneous mint. As with cases involving compromised keys, resolution depended on decisions by those controlling the protocol — including whether wrongly minted aUSD would be destroyed or whether a chain rollback would be necessary. At the time, Acala had not confirmed the final amount permanently stolen.

August 16, 2022 update

Following a statement from Acala Network's Spanish-language Twitter account, a user identified as @Jaumeelgran contacted the team, providing a wallet screenshot showing possession of the large majority of the erroneously minted aUSD, and stated publicly: "Hey, I'm an Acala holder since day one and there's no risk from me, get in touch with me via official channels, this was a fault of the system, not mine as a user."

Acala confirmed this user had triggered the bug unintentionally and was cooperating with the team to return and burn the excess aUSD. Other users who profited from the exploit did not return funds, with total stolen value estimated at approximately $1.6 million. Despite not yet returning to its full peg, the aUSD price remained above $0.90 after the protocol resumed transfers.

Credit: @alice_und_bob

Acala Network
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.