Counterexploit Salvages Stolen Funds From Platypus Hacker

After the initial hack, Platypus updated its pool contract to counterexploit $2.4 million in USDC from the hacker

article-image

DALL-E modified by Blockworks

share

Platypus, a DeFi stablecoin swapping protocol on Avalanche, was exploited for $8.5 million on Thursday evening.

The exploit occurred via a flashloan attack that took advantage of a flaw in its USP solvency check mechanism — which tricked Platypus’s smart contracts into thinking that USP was fully backed. USP is Platypus’ native stabletoken. 

Soon after the exploit, crypto community members came together to recover the funds. 

ZachXBT — a crypto scam researcher — said on Twitter that he tracked down the attacker’s wallet address after reviewing their own chain history across multiple chains.

“Your OpenSea account links directly to your Twitter and you liked a Tweet about the Platypus exploit,” ZachXBT tweeted.

Loading Tweet..

“We’d like to negotiate returning of the funds before we engage with law enforcement,” he wrote.

Platypus — meanwhile and with the help of BlockSec — updated its pool contract to counterexploit $2.4 million in USDC from the hacker.

“They updated it such that when the exploit contract deposited the USDC (which it is tricked to believe is a flash loan) as collateral for the minting of USP, they could trick the code that it owed 0 USDC back,” Twitter user nervoir said.

The USDC from the fake pool was sent to hardcoded addresses to avoid generalized front runners, nervoir tweeted. 

“The other assets will probably be harder to recover but given that they control the pool code they have significant control,” they said.

Loading Tweet..

Platypus’s stablecoin, USP, lost its peg to the dollar, dropping to $0.48. It then briefly recovered to $0.97, but has since dipped back down to $0.48, data from CoinGecko shows.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research

article-image

Turns out that owning the end-user via a crypto wallet is quite a prosperous business

article-image

The announcement followed growing speculation that Gensler would announce his exit before Trump takes office next year

article-image

HashKey Capital’s Jupiter Zheng highlighted three success areas he’s watching: Ethereum, Solana and certain tokens in DeFi

article-image

Jack explored the various AI and memecoin projects that have sprung up over the past month

article-image

If gold remains steady today, a single move from bitcoin to $98,500 would do it

article-image

Revenue estimates for the third quarter come in at $33 billion, which would be an 83% increase from the prior year