CryptoReal
CASE FILE — Mar 23, 2022

Solana Stablecoin Protocol Cashio Drained of $48 Million via Infinite Mint Bug

An anonymous attacker exploited a flaw in Cashio's collateral verification logic on Solana, minting an unlimited supply of the protocol's CASH stablecoin and ultimately converting the proceeds into roughly $48 million in ETH. The incident ranks as the 13th-largest entry on rekt's running leaderboard of crypto exploits.

Timeline of the exploit

The attack started at 08:15 UTC. Cashio's team did not issue a public statement until 09:59 UTC, when it posted on Twitter:

Please do not mint any CASH. There is an infinite mint glitch.

We are investigating the issue and we believe we have found the root cause. Please withdraw your funds from pools. We will publish a postmortem ASAP.

How the bug worked

According to analysis credited to samczsun, @madergaser, and @siintemal, the underlying issue was that Cashio's smart contract did not fully validate collateral before allowing CASH to be minted. Normally, before accepting a deposit as collateral, the contract checks that the incoming tokens match the type it already holds. However, when LP tokens were deposited through saber_swap.arrow, the contract's validation skipped checking the .mint field entirely.

This gap let the attacker construct a fraudulent root contract that was never actually checked, then build a chain of counterfeit accounts that passed validation simply because each was verified only against the previous fake account in the chain — never against a legitimate source.

An update posted March 25, 2022 added that the attacker had also circumvented the depositor_source check through a comparable trick, fabricating a fake "bank" account to satisfy the common.collateral verification step. (Full technical breakdown.)

Moving the funds

Using the fabricated collateral, the attacker was able to mint 2 billion CASH tokens. A portion of this supply was then redeemed (burned) for SaberSwap LP tokens, which were subsequently converted into 10.8 million UST and 16.4 million USDC. The remaining 1.97 billion CASH was swapped on SaberSwap for a further 8.6 million UST and 17 million USDC.

Most of the total was then bridged from Solana back to Ethereum, where it was swapped for more than 16,000 ETH (worth roughly $48 million at the time). Those funds remain held in a single Ethereum wallet.

A partial, puzzling refund

Separately, the Solana address tied to the exploiter sent out hundreds of small USDC transactions to a wide range of different addresses following the attack. About three hours after the exploit began, the attacker also embedded a message in the input data of an Ethereum transaction:

"Account with less 100k have been returned. all other money will be donated to charity."

Whether the return of smaller balances and the promise of charitable donation reflect genuine remorse, or simply an effort to reduce scrutiny and the incentive for anyone to pursue the attacker, remains an open question. Cashio indicated a full post-mortem would follow. As of this writing, the bulk of the stolen funds sits untouched in the Ethereum wallet linked above.

CashioSolana
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.