CryptoReal
CASE FILE — Jun 29, 2021

Merlin Finance Exploited a Third Time, Losses Surpass $1.5 Million

Merlin Finance's latest hack marks the third time the DeFi protocol has landed on rekt's leaderboard, and each repeat raises the same question: why do users keep entrusting it with funds?

This incident alone cost roughly $330,000, pushing the protocol's running total value lost (rekt's tongue-in-cheek take on TVL) to $1,560,000. Only a handful of protocols - Value DeFi among them - have racked up three separate entries on the rekt leaderboard.

An account using the name "Madam Merlin" shared this explanation in the project's Telegram group:

Thank you for your patience. It has been identified that this was an economic exploit.

The Merlin Dev team had deployed the Alpaca single asset vaults onto the Mainnet for testing this morning. This vault was not supposed to be publicly available or ready to launch to the public.

Via the smart contract, a hacker deposited 0.1WBNB into the vault and then manually transferred 1000BNB into the contract to trick the contract into thinking it has received 1000BNB in rewards, which resulted in the minter producing MERL rewards.

Sums referenced in this case file

We thank you for your patience.

Framing a third exploit as a matter requiring patience rather than an apology struck many observers as tone-deaf; the technical breakdown below draws on analysis credited to RugDoc.

Exploiter wallet: 0x2bADa393e53D0373788d15fD98CB5Fb1441645BD

The exploit hinged on how Merlin calculated rewards: users earned MERL tokens tied to the dollar value of performance fees they generated for the protocol, at a rate of roughly 35 MERL - worth close to $500 back then - per BNB, itself valued around $300 at the time. To work out profit, the vault converted any BNB it received into WBNB, then treated the resulting jump in WBNB balance as earnings.

Because that conversion applied regardless of where the BNB came from, tokens sent directly into the contract - not just deposits routed through the normal flow - were swept into the same profit calculation. That gap let the attacker deposit BNB, trigger a harvest, and have the full deposited amount counted as yield eligible for MERL rewards.

From there, the stolen funds moved to ETH and were routed through Tornado Cash, disappearing for good.

Merlin Labs appears to be in real trouble: its lead engineer has left, and the team has had to publicly advertise the opening, suggesting the "wizard" outfit has lost more than personnel. Rekt raised the same complaint after the previous incident, and here it is again - the team clearly still needs to try harder.

Merlin LabsR3KT
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.