One Reentrancy Bug, Two Protocols, $11.7M Gone on Gnosis Chain
A single reentrancy flaw took down two lending protocols on the same day. Agave DAO, an Aave fork, and Hundred Finance, a Compound fork, were both drained through the identical attack vector — the first exploit recorded on Gnosis (xDai) chain, and the first instance of two separate protocols being hit together in this way.
The attacker took 2116 ETH (about $5.5M) from Agave and 2363 ETH (about $6.2M) from Hundred Finance, for a combined $11.7M.

Mechanism
The root cause was the design of the xDAI token itself, which includes a callAfterTransfer() function that opens a reentrancy path. Using flash loans for initial collateral, the attacker nested repeated borrow calls inside one another, each new borrow executing before the protocol could update its recorded debt balance. Repeating the sequence let them borrow far more than their actual collateral justified. It's the same underlying vector used in CREAM Finance's $18.8M exploit the previous August. Daniel Von Fange and Mudit Gupta both examined the incident afterward.
Agave DAO: The exploit transaction landed at 11:25:40 AM UTC+1 on March 15, 2022. Funds moved to the attacker's Ethereum address, and within a few hours the 2116 ETH was routed through Tornado Cash.
Hundred Finance: The exploit transaction followed just three minutes later, at 11:28:40 AM UTC+1. Stolen funds went to a separate Ethereum address, with the 2363 ETH also sent to Tornado Cash a few hours after the attack.
Market reaction diverged: HND held up reasonably well, while AGVE dropped more than 20%.
Why forking isn't enough

Copying audited code doesn't guarantee safety once it's deployed in a new environment — the quirks of that environment can introduce risks nobody accounted for. Here, the specific behavior of Gnosis's xDai token created a hazard that didn't exist on Ethereum, where both Aave and Compound apply strict vetting to block reentrancy-prone tokens from being used as collateral. Gupta pointed to the "checks-effects-interactions" pattern as one way developers can guard against this class of bug regardless of environment.
The incident became entry #35 on the running list of DeFi's largest exploits.
Get new scam files the moment we publish them — usually 2–3 emails a week.