Donation Attack Exploits Hundred Finance's Empty WBTC Market for $7.4M on Optimism
Hundred Finance lost $7.4 million on the Optimism network in an exploit that began just after 14:00 UTC on April 15, 2023.
Rather than reading as a formal disclosure of a multi-million-dollar breach, the protocol's own statement came across more like someone reacting to news they had just stumbled across:

It looks that Hundred got hacked on #Optimism. We will update when there is more information to it.
Analysis of what actually happened is credited to Daniel Von Fange, Peckshield, Beosin and Numen Cyber.
Hundred operates as a fork of Compound, tracking lending positions through hTokens, and had passed a WhiteHatDAO audit back in February 2022. Despite that review, Von Fange identified a structural quirk that turned out to be the root cause:
the project setup two wBTC cTokens, one of which was used by the UI, one of which was empty.
That unused market became the entry point. Having first taken out a WBTC flashloan from Aave, the attacker funneled a large quantity of it directly into the dormant hWBTC contract, which distorted the exchange rate between hWBTC and WBTC. A separate rounding flaw inside the redeemUnderlying function then let that manipulated rate be converted into real, withdrawable value.
The wallet behind the theft — active on both Optimism and Ethereum — was 0x155da45d374a286d383839b1ef27567a15e67528. The theft itself ran across two transactions: 0x6e9ebcde... and 0x15096dc6....
Peckshield's assessment of the mechanics read:
The root cause appears the attacker donates 200 WBTC to inflate hWBTC's exchange rate so that even a tiny amount (2 wei) of hWBTC can basically drain current lending pools.
Beosin went further, breaking down the sequence step by step:
The root cause is that the attacker can manipulate the exchangeRate by donating a large amount of WBTC to the hWBTC contract.
In the getAccountSnapshot function, the value of exchangeRateMantissa relies on the amount of WBTC in the contract.
The attacker flashloaned 500 $WBTC, then called the redeem function to redeem the previously staked 0.3 WBTC.
Next, the attack contract 1 sent 500.3 WBTC to attack contract 2. Contract 2 used 4 BTC to mint 200 hWBTC. The redeem function was then called to redeem the 4 BTC.
Here the attacker can redeem the 4 WBTC previously staked with less than 200 hWBTC. At this point the attacker had a very small amount of hWBTC left on contract 2.
Attack contract 2 then sent 500.3 WBTC to the hWBTC contract and borrowed 1021.91 ETH via the remaining 2 hWBTCs.
Finally the attack contract 2 repaid the previous debt by using 1 hWBTC, and withdrew 500.3 WBTC from the contract.
From there, most of the proceeds were moved across a bridge to Ethereum, where they were converted into the centralized stablecoins USDT and USDC or routed into Curve pools. As of this writing, the attacker's DeBank profile still lists roughly $5.4 million held on Ethereum, with another $0.9 million remaining on Optimism.
Market reaction followed quickly: HND, the protocol's native token, lost close to half its value within 24 hours of the news breaking. It has since clawed back some ground to trade near $0.025, still well below the roughly $0.039 it commanded before the attack.
This is not the first time Hundred has taken losses of this kind. In February 2022, it absorbed $3.3 million in collateral damage when the Meter bridge was compromised. The following month, Hundred suffered a direct hit of its own: a coordinated attack drained $6.2 million from its deployment on the xDAI chain while simultaneously costing Agave DAO a further $5.5 million in the same incident. That earlier breach relied on the identical reentrancy flaw that had already taken down CREAM Finance in August 2021. Between those two prior episodes alone, Hundred's cumulative losses already totaled $16.9 million before this latest attack.
A line from coverage of that earlier Agave/Hundred incident reads just as relevant now:

Forks upon forks create a house of cards. If the code is copied and pasted, vulnerabilities can open up where they're least expected.
When one fork falls, all others have to check their foundations.
In the aftermath, Hundred urged other Compound-based forks to reach out directly, cautioning that the vulnerability amounted to "a general flaw in the code and not specific to Hundred deployment."
Perhaps taking a cue from how Euler Finance's negotiations recently played out, Hundred also put forward a bounty aimed at identifying the attacker:
48h passed since we sent an on-chain message to the hacker and tried to start negotiations with him.
Today we are launching a $500k reward in the hope that this provides additional incentive for info that leads to the Hundred attacker's arrest and the return of all funds.
Whether that added incentive succeeds in recovering the stolen funds remains to be seen.
Get new scam files the moment we publish them — usually 2–3 emails a week.