CryptoReal
CASE FILE — Sep 28, 2022

The Hunter Becomes the Hunted: 0xbad's 1,101 ETH Flashloan Heist

For 75 days, an Ethereum arbitrage bot tracked on-chain as 0xbad (0xbadc0defafcf6d4239bdf0b66da4d7bd36fcf05a) skimmed profit from other traders' mistakes. That streak ended abruptly when an unnamed counterparty drained the bot's entire treasury — 1,101 ETH in total, including 800 ETH it had only just banked — by turning a flaw in its own contract against it.

The ETH later seized had itself come from a lopsided trade. One trader tried to unload $1.85 million in Compound's cUSDC for plain USDC on Uniswap v2 and got hit by thin liquidity — only $500 came back. 0xbad spotted the mispriced trade and immediately followed it with a multi-step arbitrage across several DeFi platforms, pocketing $1.02 million.

That gain proved short-lived. According to Flashbots contributor @bertcmiller, an unidentified attacker had already found a weakness in how 0xbad handled its dYdX flashloans: the contract never restricted who could call the function used to receive loan proceeds. Lenders issuing a flashloan typically call back into a standard function on the borrower's contract to hand off execution — here, dYdX invoked 0xbad's "callFunction" — but because that entry point accepted arbitrary calls, anyone could trigger it with instructions of their own choosing.

Exploiting that opening, the attacker forced 0xbad to grant unlimited WETH approval to an address under their control, then withdrew the WETH directly from the contract.

Attacker's wallet: 0xb9f78307ded12112c1f09c16009e03ef4ef16612

0xbad's wallet: 0xbadc0defafcf6d4239bdf0b66da4d7bd36fcf05a

Sums referenced in this case file

0xbad's operator then attempted an unusual negotiation, embedding a message to the attacker inside transaction calldata:

Congratulations on this, we got careless and you sure managed to get us good, that was not easy to see. We would like this cooperate with you on resolving this matter. Return the funds to @x19603D249DF53d8b1650c762c4df316013Dce840 before September 28 at 23:59 GMT and we will consider this a whitehat, we will give you 20% of the retrieved amount as a bug bounty, payable as you see fit. Should the funds not be returned by then, we will have no choice but to pursue accordingly with everything in our power with the appropriate authorities to retrieve our funds.

The attacker was unmoved and answered in the same channel:

What about normal people who you have mev'ed and literally fucked them? Will you return them? Return the funds to all people before September 28 at 23:59 GMT and we will consider this a whitehat, we will give you 1% of the retrieved amount as a good heart sign, payable as you see fit. Should the funds not be returned by then, we will have no choice but to pursue accordingly with everything in our power with the appropriate authorities to retrieve our funds.

The episode echoes a line from rekt.news' own piece "Return to the Dark Forest," published a year earlier:

Frontrunning is vampiric. It feeds off weaker participants, while conflicts with other bots push gas prices to unusable levels. Most of the time, frontrunners win…

This time, the predator became prey. MEV extraction operates in a gray zone where code, not stated intent, decides outcomes, and in Ethereum's adversarial mempool the winner of one moment can lose everything in the next. The stolen ETH was never returned to 0xbad's operator, but few incidents have offered such a clean example of on-chain justice. Flashbots' Bert Miller captured the mood succinctly: bad code, great content.

MEV
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.