Paraluni hack — March 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 13, 2022 |
| Target type | Other |
| Loss | $1,700,000Price at time of incident |
| Method | ReentrancyThe MasterChef contract's depositByAddLiquidity function accepted a pool identifier and a token array without checking that the tokens matched the LP token registered for that pool, and the internal add-liquidity routine had no reentrancy guard. The attacker deployed two ERC-20 tokens, UBT and UGT, whose transferFrom called back into MasterChef.deposit before the first deposit's accounting was written, crediting the same LP tokens twice. A PancakeSwap flash loan supplied the working capital. |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
Paraluni was a BNB Chain yield-farming and metaverse project whose staking contract was a fork of SushiSwap's MasterChef. On 13 March 2022, at about 00:04 UTC, an attacker drained it through a reentrancy bug. The contract's depositByAddLiquidity function took a pool identifier and an array of token addresses but never checked that those tokens corresponded to the LP token registered for that pool, and the internal add-liquidity routine carried no reentrancy guard. The attacker deployed two ERC-20 tokens, UBT and UGT, with a modified transferFrom that called back into MasterChef.deposit before the first deposit's accounting had been written. Each cycle credited the same LP tokens twice, letting the attacker withdraw more than had been supplied. CertiK's reconstruction shows the pattern: a PancakeSwap flash loan of roughly 157,000 USDT and 157,000 BUSD, used to mint about 155,935 ParaPair LP tokens, with the doubled credit then unwound, the loan repaid and the difference kept. The attack was repeated across a series of transactions rather than executed once. Published figures converge on approximately $1.7 million. The attacker swapped the proceeds into BNB and then ether, bridged from BNB Chain to Ethereum, and deposited roughly 660 ETH into Tornado Cash across twelve instalments. CertiK recorded the attacker address and the initial attack transaction. No funds were recovered, no individual has been identified or charged, and both CertiK and Halborn attributed the loss to unvalidated user input combined with the missing reentrancy guard.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Transactions
- 0x70f367b9420ac2654a5223cc311c7f9c361736a39fd4e7dff9ed1b85bab7ad54
Attacker addresses
- 0x94bc1d555e63eea23fe7fdbf937ef3f9ac5fcf8f
Sources
- CertiKSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- CoinCodeCapSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Paraluni hack — March 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/paralunihttps://itokenly.com/hacks/paraluniPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.