CryptoReal
CASE FILE — Oct 12, 2022

Unvalidated Migration Parameter Lets Attacker Drain $2.3M From STAX

STAX, a protocol tied to TempleDAO, was exploited the day before this report for approximately $2.3 million worth of LP tokens.

TempleDAO began life as one of the many Olympus (OHM) fork projects that emerged ahead of the market's peak the previous year, before pivoting toward stablecoin yield farming once the original Olympus-style tokenomics collapsed. These days, Temple's main focus is generating yield on FRAX3CRV through Convex, with STAX operating as part of the project's "flywheel system" — described by the team as "a reward boosting liquidity layer for the FRAX/TEMPLE gauge."

Community enthusiasm, once strong enough to resemble a cult following, appeared to be fading even before the exploit. The day prior, community member DCF GOD had responded to a TempleDAO sentiment check with: "After a year of it, I'm low on hope."

Spreek was the first to flag the exploit publicly, roughly an hour after it happened, and STAX subsequently confirmed the incident. While the loss is unlikely to threaten TempleDAO's broader protocol, the mechanics behind it are hard to read charitably — particularly given that the vulnerable contract had been live since June, raising the question of why it took so long to be found and exploited.

The flaw itself was straightforward: the StaxLPStaking contract's migrateStake() function never validated that the oldStaking parameter it received was legitimate. That gap meant anyone could deploy their own contract referencing the same oldStaking value, then set an arbitrary deposit amount and choose the address the funds would be sent to.

Sums referenced in this case file

Exploiting this, the attacker extracted roughly 320,000 Stax FRAX/TEMPLE LP tokens, which were then swapped for ETH inside the attacker's contract.

Attacker's address: 0x9c9fb3100a2a521985f0c47de3b4598dafd25b01

Attack transaction: 0x8c3f442fc6d640a6ff3ea0b12be64f1d4609ea94edd2966f42c01cd9bdcf04b5

The exploiter's wallet had been funded via Binance shortly before the attack, and the stolen funds were then moved to a separate address, 0x2b63d4a3b2db8acbb2671ea7b16993077f1db5a0, where they have remained since.

Set against TempleDAO's overall size, the loss is comparatively modest — the protocol's total value locked was around $57 million at the time, according to DeFiLlama. STAX stated that "remediations will be made for all affected users."

The bigger cost may end up being reputational, given how basic the underlying error was to have reached a live production contract. TempleDAO pointed out that its Temple Core Vaults remain secure and share no code with the affected STAX contracts. Even so, the incident leaves open whether the community's already-thinning faith in the project can hold.

TempleDAO
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.