CryptoReal
CASE FILE — Jan 17, 2023

Flash Loan Exploit Drains $660,000 From Jarvis Network Pool Through Midas Capital Collateral Flaw

Roughly $660,000 disappeared from a lending pool tied to Jarvis Network's jFIAT stablecoins this past Sunday, after attackers used a flash loan to target Midas Capital, a Polygon-based money market. The stablecoins themselves were not flawed — the opening came through a collateral asset Midas had approved only shortly beforehand.

Statements from both projects — Midas Capital and Jarvis Network — pointed to the same culprit: a WMATIC-stMATIC Curve LP token recently whitelisted as collateral. That category of LP token carries a well-documented read-only reentrancy flaw, the same bug class responsible for a $220,000 loss at market.xyz back in October, as laid out at the time in a post-mortem from QuillAudits.

The underlying problem is how these Curve LP tokens report their virtual price: a protocol that integrates the token without guarding against reentrant calls can be made to read a manipulated value mid-transaction. That is effectively what happened to Midas.

BlockSec laid out a technical breakdown of the exploit (credit also to Beosin), describing five steps that hinge on a single timing gap in how a position's collateral value gets calculated:

  1. the calculation of a position's collateral depends on self.D and totalSupply

  2. self.D is updated after an unexcepted callback, so the four borrows in step 5 to use an outdated self.D.

  3. the contract burns stMATIC-f before the unexcepted callback, which causes the four borrows in step 5 to use an updated stMATIC-f.totalSupply().

As a result, @MidasCapitalxyz over-estimated the attack contract's position and lent excessive assets to the contract.

Stated plainly, the attacker engineered a gap between when self.D refreshed and when the LP token's supply figure updated relative to an outside callback. Midas's contracts consequently misjudged the attacker's position as far larger than it really was and issued loans accordingly.

Attacker wallet: 0x1863b74778cf5e1c9c482a1cdc2351362bd08611

Sums referenced in this case file

Exploit transaction: 0x0053490215baf541362fc78be0de98e3147f40223238d5b12512b3e26c0a2c2f

Compromised contract: 0x5bca7ddf1bcccb2ee8e46c56bfc9d3cdc77262bc

Leveraging that phantom collateral value, the attacker drew out 273,973 jCHF, 368,058 jEUR, 45,250 jGBP, and 45,435 agEUR from the protocol.

Those stablecoins were converted into roughly 660,000 MATIC — about $660,000 — then forwarded to Kucoin and Binance.

The episode repeats a familiar pattern in DeFi: a loss built on a vulnerability the industry had already flagged, for which straightforward fixes already existed.

Jarvis Network said it would absorb the roughly $350,000 gap left in jFIAT backing by the exploit, and Midas Capital said it had opened communication with the attacker in hopes of negotiating a bounty.

Pascal Tallarida, Jarvis Network's founder, gave rekt.news the following statement on how the protocol intends to proceed:

As a result of the Midas exploit, the protocol lost 257k jEUR, 237k jCHF and 45k jGBP, and users lost 111k jEUR and 36k jCHF. The jFIATs belonging to the protocol were not collateralized.

We have decided to do not wait after Midas, and we are working on a plan to re-collateralize the jFIATs the protocol lost, and reimburse the users who were victim of the exploit. We will propose to the Jarvis governance to allocate part of the protocol's revenus (liquidity provision, lending interests, protocol fee and farming with POL) and part of the protocol treasury to it, and we will ask for the help and support of our community, partners, investors, and "frens". I have already discussed with many of them and they have expressed their will to support us in this difficult moment, either with or without counterparty. Also, the company which is the main liquidity provider within the protocol, will help, with both its treasury and revenues (±$700k last year with swap fees, interests and market making).

Then, Midas promised us that they will do right by us, by reimbursing what they can, and by helping us to provide value to the protocol. It could take them a while to do so, but I trust that they will do it.

Collateral assets approved without adequate vetting have produced losses like this before, and nothing about this case suggests it will be the final one.

Jarvis NetworkMidas Capital
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.