Elephant Money hack — April 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 12, 2022 |
| Target type | Stablecoin or yield protocol |
| Loss | $11,200,000Price at time of incident |
| Method | Oracle or price manipulationThe ElephantReserve contract valued the native ELEPHANT token from spot automated market maker reserves when minting and redeeming the TRUNK stablecoin. Using flash-loaned capital (roughly 131,000 WBNB and 91 million BUSD borrowed from PancakeSwap pairs) the attacker bought ELEPHANT to inflate that spot price, minted TRUNK against the inflated valuation, then redeemed TRUNK for the reserve's real WBNB and BUSD before repaying the loans. Repeated over several cycles inside a single transaction sequence. |
| Chains | BNB Chain |
| Audited beforehand | CertiK; Solidity Finance |
| Outcome | Unresolved |
What happened
On 12 April 2022 an attacker drained the reserve backing Elephant Money's TRUNK stablecoin on BNB Chain. The protocol minted and redeemed TRUNK against a valuation of its native ELEPHANT token read from spot automated market maker reserves, so anyone able to move the ELEPHANT price could mint TRUNK cheaply and redeem it for the reserve's real assets.
The attacker borrowed roughly 131,000 WBNB and 91 million BUSD through flash loans from PancakeSwap pairs, used the borrowed capital to buy ELEPHANT and inflate its price, minted TRUNK at the inflated valuation, then redeemed TRUNK for WBNB and BUSD before repaying the loans. Elephant Money said the sequence executed inside a single smart contract transaction and that over $261 million in volume was needed to push through the protocol's defences. Security firm BlockSec, whose analysis was cited by The Record and PYMNTS, said the attacker simply repeated the process, netting roughly $4 million per cycle.
Elephant Money's own post-mortem puts the permanent loss at 27,416 BNB, about $11.2 million at the time, and that figure is used by the independent reporting. Higher figures of around $22 million appear in third-party trackers; those add the ELEPHANT tokens removed from the liquidity pool to the BNB actually extracted, so they measure a different quantity rather than contradicting the protocol's accounting. ELEPHANT fell about 76 percent after the attack.
Elephant Money said the proceeds were laundered through Tornado Cash and sent to Ethereum via decentralised bridges. The team paused the ElephantReserve, Stampede and TRUNK minting and redemption, deployed $2.5 million of BUSD from treasury to rebuild reserves with a further $2.5 million held in reserve, and offered the attacker a 10 percent bounty, roughly $1.12 million, to return the remainder. No funds were returned and no arrests have been reported. On audit status, Elephant Money said the ElephantReserve had been audited and reviewed with Solidity Finance while its code remained closed source, that it engaged CertiK and DeFi insurer InsurAce to investigate after the attack, and that PeckShield would audit the Reserve and Stampede contracts going forward.
Sources
- Elephant Money (Bankteller)Primary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
- PYMNTSSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/elephant-money/reserve-exploit-52fd36ccc7e8
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Elephant Money hack — April 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/elephant-moneyhttps://itokenly.com/hacks/elephant-moneyPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.