CryptoReal
CASE FILE — May 8, 2021

Same Attacker Behind Value DeFi Hack Strikes Rari Capital's ETH Pool Hours Later

Rari Capital, a yield aggregator known partly for the young age of its development team, became the second victim of the same attacker in a single day on May 8, 2021. Hours after draining Value DeFi, the same wallet turned to Rari's ETH pool, removing roughly $10 million worth of ETH.

The project's youth had already made it a subject of community debate over whether developer age correlates with security competence in an industry that is itself only two to three years old. Whatever one's view on that question, the losses were real for the people affected.

01A repeated cross-chain technique

The attacker used proceeds from the Value DeFi hack to bankroll the follow-up strike on Rari, effectively running the same playbook across two chains. On BSC, 5,346 BNB (about $3.8 million) was stolen and converted to roughly 1,000 ETH via the following steps:

  1. Create a fake token and pair it with BNB on PancakeSwap in order to interact with Alpaca Finance.
  2. Call approve() on the fake token against Alpaca Finance, triggering a payload that lets the attacker draw on VSafe through the Codex farm to obtain vSafeWBNB.
  3. Convert the vSafeWBNB into WBNB.
  4. Bridge the WBNB to Ethereum via Anyswap.

This four-step sequence was executed twice on BSC.

Sums referenced in this case file

The Rari-specific attack followed a parallel structure:

  1. Create a fake token and pair it on SushiSwap.
  2. Interact with Alpha Homora, triggering a payload that lets the attacker obtain ibETH inside Rari's ETH pool contract.
  3. Convert that ibETH into ETH within the Rari pool.

That sequence pulled out 2,900 ETH (about $11.1 million), with an additional 1,700 ETH at risk before Rari's team intervened. Combined across both protocols, the attacker's total haul reached approximately $15 million in ETH. Credit for the technical analysis goes to Frank Researcher.

Rari's governance token, $RGT, dropped sharply in price in the wake of the disclosure.

02A message, then cold feet

At one point the attacker apparently tried to post a public message via an on-chain transaction, then attempted to cancel it — but set the gas price too low for the cancellation to process. The result was a roughly 20-minute delay before the cancellation cleared, giving observers ample time to see the message before it could be withdrawn. Credit to banteg and dudesahn for spotting this.

03Broader implications

The method bore a strong resemblance to the earlier "Evil Pickle Jar" exploit, and this kind of cross-protocol replay looks likely to become more common as DeFi composability increases. Even though the specific protocols differed — Alpaca versus Alpha Homora, vSafe versus Rari, PancakeSwap versus SushiSwap — the underlying exploit mechanism carried over cleanly from one chain to the next, illustrating how tightly interconnected DeFi money-legos can turn a single vulnerability into a multi-chain, multi-victim event. Given the anonymity common to attackers in this space, meaningful legal consequences for incidents like this remain unlikely.

Rari Capital
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.