T
iTokenly

ParaSpace hack — March 2023

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 17, 2023
Target typeLending protocol
Loss$5,000,000Published estimates range $4,900,000 to $5,000,000Price at time of incident
Recovered$4,900,000
MethodContract logic errorCollateral valuation error in cAPE, ParaSpace's auto-compounding wrapper for staked ApeCoin. _getTotalPooledApeBalance() derived the cAPE rebasing index from the total APE staked in the protocol's position, and ApeCoinStaking.depositApeCoin() could be used to increase that staked amount. Inflating the pooled balance inflated the value of the attacker's cAPE collateral and allowed an oversized borrow of USDC and WETH. The position was bootstrapped with a flash loan of about 47,352 wstETH, of which roughly 46,018 wstETH was supplied to borrow cAPE.
ChainsEthereum
Audited beforehandCertiK, which said the vulnerable code was added after its audit and was outside its scope; ParaSpace reported nine audits in total
OutcomePartially recovered

What happened

ParaSpace, an NFT-collateralised lending protocol on Ethereum, was attacked on 17 March 2023 through a flaw in how it valued cAPE, its auto-compounding wrapper around staked ApeCoin.

BlockSec and CertiK both traced the bug to _getTotalPooledApeBalance(), which derived the cAPE rebasing index from the total APE staked in the protocol's position. Because ApeCoinStaking.depositApeCoin() could be used to add to that staked balance, an attacker could inflate it. BlockSec records the staked amount rising from 851,662 to 3,183,876 APE, a roughly 3.7-fold increase, which inflated the value of the attacker's cAPE collateral and let them borrow far more USDC and WETH than it was worth. The position was funded with a flash loan of about 47,352 wstETH, of which roughly 46,018 wstETH was supplied to borrow cAPE.

The attacker's first three attempts failed, between 03:51 and 04:36 UTC, with escalating gas limits. BlockSec's Phalcon monitoring system detected the activity and BlockSec sent a rescue transaction at 05:47:11 UTC that captured 2,906 ETH, around $5 million at the time, before the attacker succeeded; CertiK gives the figure as 2,909 ETH. The rescued funds were returned to ParaSpace. BlockSec's published write-ups do not describe how the rescue transaction was constructed. ParaSpace said its residual loss was 50 to 150 ETH, under $270,000, caused by price slippage during the attack and the rescue, and that it would cover it. It also added time-locks on large withdrawals.

The attacker was never identified, and asked in an on-chain message for 0.7 ETH of gas fees to be returned. In May 2023 ParaSpace team members publicly accused chief executive Yubo Ruan of failing to account for over half of the recovered ETH, alleging that roughly $1 million had been moved to unidentified wallets and converted to cash. Ruan denied the allegations, said the residual amount had been repaid in full according to a planned schedule, and characterised the accusations as an attempt to force him to step down as chief executive. The dispute was not publicly resolved.

Sources

  1. BlockSecSecondary · retrieved 2026-08-01
  2. BlockSecSecondary · retrieved 2026-08-01
  3. CertiKSecondary · retrieved 2026-08-01
  4. CryptoSlateSecondary · retrieved 2026-08-01
  5. BitDegreeSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "ParaSpace hack — March 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/paraspace
https://itokenly.com/hacks/paraspace

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.