Abracadabra.money (Cauldrons) hack — January 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 30, 2024 |
| Target type | Lending protocol |
| Loss | $6,490,000Published estimates range $6,490,000 to $6,500,000Price at time of incident |
| Method | Contract logic errorAn accounting inconsistency in the Cauldron borrow logic. Calling repayForAll() set the elastic side of the totalBorrow structure to zero without also zeroing the base side, leaving the two out of step. Repeatedly calling userBorrowPart() and repay() against that inconsistent state drove the borrow 'part' value up exponentially through precision loss, which allowed the solvency check to be bypassed and a large MIM loan to be drawn against collateral that did not support it. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 30 January 2024 an attacker drained about $6.49 million of Magic Internet Money from Abracadabra.money's cauldrons on Ethereum. PeckShield first flagged the transactions and CertiK attributed the cause to a rounding error. Coverage cites either $6.49 million or $6.5 million, which are the same estimate rounded differently.
Cauldrons are Abracadabra's isolated lending markets, where users deposit interest-bearing collateral and borrow the MIM stablecoin against it. The defect lay in how total debt was tracked. When repayForAll() was called it zeroed the elastic side of the totalBorrow structure but not the base side, leaving the two inconsistent. By repeatedly calling userBorrowPart() and repay() against that state, the attacker drove the borrow 'part' value up exponentially through precision loss, which let the insolvency check be bypassed and a heavily inflated MIM loan be taken against collateral that did not support it. The attack contract was funded with 1 ETH routed through Tornado Cash.
Selling the borrowed MIM broke the stablecoin's peg. MIM fell to about $0.76 to $0.77 within an hour of the exploit becoming public, recovered to around $0.94 the same day and was near $0.98 by the following morning.
The MIM team said its engineers were triaging the incident and that the DAO treasury would buy MIM back from the market and burn it to stabilise the peg. Hours later it told users to revoke all smart-contract approvals. The attacker was not identified and the funds were not recovered.
Sources
- UnchainedSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- Extropy.IOSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Abracadabra.money (Cauldrons) hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/abracadabra-money-cauldronshttps://itokenly.com/hacks/abracadabra-money-cauldronsPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.