Platypus Finance hack — February 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 16, 2023 |
| Target type | Decentralised exchange |
| Loss | $9,190,000Published estimates range $8,500,000 to $9,200,000Price at time of incident |
| Recovered | $2,400,000 |
| Method | Contract logic errorOrdering flaw in MasterPlatypusV4::emergencyWithdraw on Avalanche: the USP solvency check ran before LP token balances were updated, so a borrower could withdraw collateral while leaving the borrowed USP debt outstanding. Flash-loaned capital was used to scale the position, but the flash loan was not the vulnerability. |
| Chains | Avalanche |
| Audited beforehand | Omniscia (its prior audits did not cover the exploited MasterPlatypusV4, USP or PlatypusTreasure contracts) |
| Attributed to | Mohammed M. and his brother Benamar M. (French nationals, named by initials in reporting; prosecuted in Paris and both fully acquitted on 3 December 2023 — no criminal culpability was established)Confirmed |
| Outcome | Arrests or charges |
What happened
On 16 February 2023 at 19:16:54 UTC, the Avalanche stableswap protocol Platypus Finance was drained through a logic error in its MasterPlatypusV4 staking contract.
The attacker flash-borrowed about 44 million USDC, deposited it as collateral, minted roughly 41.79 million of Platypus's USP stablecoin against it, then called emergencyWithdraw to pull the collateral back out. The solvency check in that function ran before the staked LP balances were updated, so the withdrawal succeeded while the USP debt remained unpaid. The attacker then liquidated the USP across Platypus's stablecoin pools. Auditor Omniscia, which published the technical post-mortem, confirmed the standard withdraw function performed the same checks in the correct order and that the exploited contracts had never been in scope of any audit it conducted. Two further transactions reused the same bug.
Figures differ by what is counted. Platypus's own accounting put the total at $9.19 million across three attacks: roughly $8.5 million in the first, about $380,000 in the second and about $287,000 in the third. CoinDesk's tally of all three came to $9.2 million. Omniscia's $8.5 million is narrower still: it is an estimate of profit retained from stablecoin liquidations and explicitly excludes the USP component as indeterminate in value, so it is a partial count rather than a lower estimate of the same total.
Within 24 hours Platypus and BlockSec executed a counter-transaction recovering about $2.4 million in USDC, and Tether froze $1.5 million in USDT. Platypus guaranteed users a minimum 63% of funds, rising to about 78% if the frozen USDT was reminted and an Aave governance proposal passed, and opened a compensation portal.
Two French brothers were arrested and prosecuted over the incident. On 3 December 2023 a Paris court acquitted both in full, holding that calling a publicly available smart contract's emergency withdrawal function constituted neither fraud nor unauthorised access to a computer system. No criminal culpability was established; the court noted Platypus could still pursue civil remedies.
Law enforcement
French police arrested two brothers days after the exploit; investigator ZachXBT and Binance were credited with supplying the identifying information. Prosecutors sought five years' imprisonment for the elder brother. On 3 December 2023 a Paris criminal court acquitted both, reasoning that the smart contract was publicly accessible so unauthorised-access charges did not apply and that using the protocol's own emergency withdrawal function did not constitute fraud; the derived money-laundering and receiving-stolen-goods charges fell away. The judges noted Platypus could still sue in civil court. First reported by Le Monde.
Sources
- Platypus FinancePrimary · retrieved 2026-08-01
- Omniscia (Platypus auditor)Primary · retrieved 2026-08-01
- ImmunefiSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The Block (citing Le Monde)Secondary · retrieved 2026-08-01
- SnowtraceOn-chain · retrieved 2026-08-01
Official post-mortem: https://medium.com/@omniscia.io/platypus-finance-incident-post-mortem-7b71a0a47a5e
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Platypus Finance hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/platypus-financehttps://itokenly.com/hacks/platypus-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.