CryptoReal
CASE FILE — May 1, 2022

Reentrancy Bug in Forked Compound Code Drains $80M from Rari Fuse Pools

Seven of Rari's Fuse pools were emptied of roughly $80 million in a window running from about 9:00 to 9:35 AM UTC on April 30th.

A Rari-affiliated account had insisted beforehand that "none of the arbitrum pools are vulnerable." That reassurance didn't hold: the same attacker went on to hit the Arbitrum deployment as well, though that leg of the attack netted a comparatively small ~100 ETH.

It's the second time this has happened to the protocol — Rari was hacked previously — leaving the community hoping a repeat wasn't in store.

Analysis credit: Hacxyk, Certik.

Rari's codebase is a fork of Compound, which does not follow the check-effects-interactions pattern. That structural choice has been behind several prior reentrancy incidents across the ecosystem, including at CREAM, Hundred, and Voltage/Ola.

Here, the reentrancy path ran through CEther's use of call.value to move ETH. When the recipient of that ETH is a contract, call.value hands control back to the receiving contract, opening the door to a second, unintended call before the first has finished.

The underlying issue had actually been flagged back in early March, and Rari responded by upgrading the CToken and Comptroller contracts. That patch, however, left one function outside its protections: exitMarket on the Comptroller contract.

exitMarket releases a deposit from its role as collateral so it can be withdrawn, provided no loan is outstanding against it. Because Compound-style code checks conditions after the funds have already moved (a consequence of not following check-effects-interactions), a transaction can withdraw collateral before the system has recorded a matching borrow as debt.

The attacker exploited this sequencing by taking out flash loans of ETH, then reentering through call.value to invoke exitMarket — pulling out the flash-loaned collateral while still holding onto the borrowed ETH.

Attack sequence, reconstructed step by step using sample transaction 0xab4860…:

  1. The attacker flash-borrowed 150,000,000 USDC and 50,000 WETH.
  2. The 150,000,000 USDC was deposited as collateral into the fUSDC-127 contract — one of the vulnerable Compound-fork pools.
  3. Using that collateral, the attacker called borrow() to draw out 1,977 ETH.
  4. borrow() itself skips the check-effects-interactions ordering: it sends the ETH out before the attacker's borrow position is updated on record.
  5. With that borrow record still unset, the attacker's fallback function reentered exitMarket(), letting them pull out the entire 150M USDC collateral deposit.
  6. This sequence was then repeated across several additional tokens and pools.
  7. The flash loans were repaid, the remaining profit was moved to the attacker's own address, and part of it was routed onward through Tornado Cash.
Sums referenced in this case file

Fuse pools hit: 8, 18, 27, 127, 144, 146, 156

Relevant addresses:

Funds taken by asset:

  • 6,037.8139071514 ETH
  • 20,251,603.11559831 FEI
  • 14,278,990.684390573 DAI
  • 1,948,952.1788665 LUSD
  • 10,055,556.328173 USDC
  • 132,959.9008 USDT
  • 31,615.8714 RAI
  • 13,101,364.94 FRAX
  • 2,765,891 UST

Combined estimated value: $79,749,026

The attacker started routing the haul through Tornado Cash but paused after moving only about 5,400 ETH (roughly $15M) — leaving roughly $62.7M sitting untouched in the wallet. That pause raised the question of whether they were weighing Rari's bounty offer for the funds' return.

Tribe DAO seemed to think so, sending this message on-chain via an Etherscan transaction:

We noticed you may be considering the no-questions-asked $10m offer. If you wish to take us up on this, please deposit the remaining funds to the Tribe DAO Timelock: 0xd51dbA7a94e1adEa403553A8235C302cEbF41a3c

Every project built on a Compound fork now has reason to audit its own code for the same class of bug. As researcher 0x_b1 noted:

this exploit had been fixed in Compound code some time ago, but was changed to its previous form in this commit by developers

There's a particularly unfortunate footnote: someone had directly asked Rari whether the Arbitrum pools were safe and was told yes — only to be caught in the second wave of the same exploit hours later. A basic double-check might have spared that second round of losses entirely.

Rari now sits at #10 on the leaderboard of exploits.

FeiRari
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.