CryptoReal
CASE FILE — Oct 13, 2023

Platypus Finance Hit Again, Losing $2.2M in Third Exploit of the Year

Platypus, the Avalanche-based stableswap protocol, has suffered another flash loan attack, this time losing $2.2 million. It's the third time the project has appeared on rekt's radar.

The first incident came in February, when Platypus lost $8.5M after its newly-launched stablecoin was compromised, also through a flash loan. That earlier attacker made a costly error, failing to build in any mechanism to withdraw funds from the exploit contract, which let BlockSec whitehat-recover 2.4M USDC and return it. Poor operational security also meant the attacker was quickly identified and was later arrested in France. A second, smaller incident in July cost the protocol $150,000.

This latest attack was first flagged by Peckshield, with losses climbing as the incident unfolded. Platypus subsequently confirmed the breach, saying it had suspended all pools as a precaution given suspicious activity on the protocol. With three separate exploits inside eight months, questions are mounting over how much longer the protocol can withstand repeated attacks.

Credit for analysis of the exploit goes to BlockSec and Inspex.

The attack consisted of three separate transactions, each relying on flash loans to distort pricing inside Platypus's LP-AVAX pool. According to BlockSec, the attacker manipulated the pool's internal "cash" and "liability" figures, which in turn skewed the swap price through slippage.

Inspex laid out the mechanics in a step-by-step breakdown:

Sums referenced in this case file
  1. The attacker deposits WAVAX into LP-AVAX and sAVAX into LP-sAVAX, inflating the liability recorded by both LP contracts.
  2. The attacker swaps sAVAX for WAVAX, reducing the cash held by the LP-AVAX contract.
  3. The attacker withdraws WAVAX from LP-AVAX, stripping out the remaining available cash. This pushes up the slippageFrom value, which distorts the resulting actualToAmount.
  4. The attacker then executes a swap that profits from this manipulated slippage.

As in the February incident, a mistake by the attacker allowed for partial recovery of the stolen funds — $575,000 in this case.

On-chain details:

The remainder of the stolen assets — $1.6 million in WAVAX and sAVAX — is still sitting in the primary attack contract. Hummus Exchange, a fork of Platypus, paused its own contracts as a precaution against a similar attack.

Notably, Platypus had been audited by both Hacken and Omniscia, but those audits were completed by early January 2022 — more than three months before the vulnerable contract was even deployed.

The broader Avalanche ecosystem has had a difficult stretch. The prior weekend's Stars Arena incident drew little response from the AVAX community, and while 90% of the funds involved there were eventually returned, how both the project team and Ava Labs' CEO handled communications left a poor impression. Separately, Trader Joe, one of Avalanche's most prominent DEXs, was reported to be facing a lawsuit — from the unrelated coffee chain Trader Joe's. Against a backdrop of struggling alternative L1s, some of which are pivoting toward the more active Ethereum L2 ecosystem, questions remain about Avalanche's path forward.

AvalanchePlatypus Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.