ApeRocket Finance hack — July 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 14, 2021 |
| Target type | Other |
| Loss | $1,260,000Price at time of incident |
| Method | Flash loan attackVault performance-fee accounting counted any tokens sitting in the contract as earned yield. Using flash loans the attacker took ~99% of a vault's shares, then inflated the vault's apparent profit so that harvest/withdraw minted the vault's reward token (SPACE on BNB Chain, pSPACE on Polygon) almost entirely to the attacker, who sold it and repaid the loan. On BNB Chain the profit was inflated by transferring a large CAKE balance directly into the vault; on Polygon, per WatchPug, by exploiting deposit() accepting deposits to another address together with ApeSwap's MiniApeV2 contract allowing deposits to any address. |
| Chains | BNB Chain, Polygon |
| Outcome | Unresolved |
What happened
ApeRocket, a yield-farming aggregator running vaults on BNB Chain and Polygon, was drained twice on 14 July 2021 in two attacks sharing one root cause. CoinDesk reported the combined loss at $1.26 million.
Both vaults derived performance fees from the token balance held by the contract, without separating yield the vault had actually earned from tokens someone had simply sent to it. In the first attack, at about 04:30 UTC, the attacker took a PancakeSwap flash loan of 1.6 million CAKE, deposited 509,000 CAKE to take roughly 99.5% of the CAKE vault, then transferred a further 1.1 million CAKE directly into the vault contract and called harvest. The contract read the injected balance as profit and minted about 508,000 SPACE reward tokens, nearly all to the attacker, who swapped them back to CAKE and repaid the loan. Security firm WatchPug traced that vault's loss at $260,000, or 883 BNB.
About three and a half hours later the same pattern was used against the MATIC-DAI vault on Polygon. Aave flash loans of 24 million DAI and 54 million MATIC were used to build and deposit an outsized LP position, causing the vault to mint 2.5 million pSPACE as performance rewards; the attacker converted these to 521 ETH, worth roughly $1 million.
The SPACE token fell about 63%. ApeRocket said it would mint no further SPACE while it arranged compensation for holders and promised details later that week. No public accounting of what was ultimately paid has been located.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "ApeRocket Finance hack — July 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aperockethttps://itokenly.com/hacks/aperocketPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.