T
iTokenly

Abracadabra.money (Cauldrons) hack — January 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 30, 2024
Target typeLending protocol
Loss$6,490,000Published estimates range $6,490,000 to $6,500,000Price at time of incident
MethodContract logic errorAn accounting inconsistency in the Cauldron borrow logic. Calling repayForAll() set the elastic side of the totalBorrow structure to zero without also zeroing the base side, leaving the two out of step. Repeatedly calling userBorrowPart() and repay() against that inconsistent state drove the borrow 'part' value up exponentially through precision loss, which allowed the solvency check to be bypassed and a large MIM loan to be drawn against collateral that did not support it.
ChainsEthereum
OutcomeUnresolved

What happened

On 30 January 2024 an attacker drained about $6.49 million of Magic Internet Money from Abracadabra.money's cauldrons on Ethereum. PeckShield first flagged the transactions and CertiK attributed the cause to a rounding error. Coverage cites either $6.49 million or $6.5 million, which are the same estimate rounded differently.

Cauldrons are Abracadabra's isolated lending markets, where users deposit interest-bearing collateral and borrow the MIM stablecoin against it. The defect lay in how total debt was tracked. When repayForAll() was called it zeroed the elastic side of the totalBorrow structure but not the base side, leaving the two inconsistent. By repeatedly calling userBorrowPart() and repay() against that state, the attacker drove the borrow 'part' value up exponentially through precision loss, which let the insolvency check be bypassed and a heavily inflated MIM loan be taken against collateral that did not support it. The attack contract was funded with 1 ETH routed through Tornado Cash.

Selling the borrowed MIM broke the stablecoin's peg. MIM fell to about $0.76 to $0.77 within an hour of the exploit becoming public, recovered to around $0.94 the same day and was near $0.98 by the following morning.

The MIM team said its engineers were triaging the incident and that the DAO treasury would buy MIM back from the market and burn it to stabilise the peg. Hours later it told users to revoke all smart-contract approvals. The attacker was not identified and the funds were not recovered.

Sources

  1. UnchainedSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. Extropy.IOSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Abracadabra.money (Cauldrons) hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/abracadabra-money-cauldrons
https://itokenly.com/hacks/abracadabra-money-cauldrons

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.