CryptoReal
CASE FILE — Feb 16, 2023

Flash Loan Exploit Drains $8.5M From Avalanche Stablecoin Platypus Finance

Platypus Finance, an Avalanche-based stableswap AMM, lost $8.5 million to a flash loan exploit targeting its newly launched stablecoin, USP, just ten days after the token went live. The attack left USP badly undercollateralized and pushed it off its dollar peg.

The team confirmed the breach shortly after it occurred, stating that the attacker had exploited a logic flaw in the solvency-check mechanism of the contract holding USP's collateral, using a flash loan to do so. The irony was not lost on observers: a prior announcement about USP's launch had promoted it as offering "an extra layer of protection from the volatility that other stablecoins may experience."

Security researchers Daniel Von Fange and Peckshield were credited with analyzing the incident.

The root cause traced back to how the protocol validated withdrawals. The attacker began by taking out a flash loan of 44 million USDC, depositing it into Platypus to receive LP tokens. Those LP tokens were then pledged as collateral to borrow 41.7 million USP. The vulnerability lay in the emergencyWithdraw() function, which checked only whether a position was solvent at that instant, without accounting for outstanding borrowed funds. This gap let the attacker pull out the deposited collateral while still holding onto the borrowed USP.

With the collateral in hand, the attacker repaid the original flash loan and then dumped the borrowed USP through Platypus's own pools, draining liquidity from paired stablecoins including USDC, USDT, DAI, and BUSD in the process.

Sums referenced in this case file

Relevant on-chain identifiers:

The dumping of USP for other stablecoins pushed its peg down by more than 50%. The $8.5 million taken has remained sitting in the attacker's contract, though $1.5 million of the stolen USDT was subsequently frozen by its issuer.

The relative simplicity of the exploit, combined with the attacker's choice to hold funds in easily-blacklisted, centralized stablecoins rather than converting to something less traceable or routing through a mixer, pointed to a less sophisticated actor than is typical for exploits of this size.

Within hours, on-chain investigator ZachXBT identified the attacker by tracing an ENS address connected to the exploiter's transaction history back to now-deleted social media accounts using the same handle. Platypus subsequently reached out to the identified individual, stating that it was arranging a bounty and inviting the hacker — along with anyone else with relevant information — to come forward.

AvalanchePlatypus Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.