Platypus Finance (October 2023) hack — October 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 12, 2023 |
| Target type | Decentralised exchange |
| Loss | $2,230,000Published estimates range $2,200,000 to $2,230,000Price at time of incident |
| Recovered | $575,000 |
| Method | Flash loan attackThree flash-loan-funded transactions, sent from two externally owned addresses, manipulated the pricing math of the WAVAX and sAVAX main pools. CertiK records the first attacker flash-borrowing 1.1 million WAVAX and 991,000 sAVAX, depositing them for Platypus LP tokens, then routing swaps between the pools and withdrawing in a sequence that distorted each pool's cash-to-liability coverage ratio. Because Platypus derives swap pricing and slippage from that ratio, subsequent swaps settled at favourable rates and the attacker kept the difference after repaying the loans. Neptune Mutual locates the flaw in the _quoteFrom and _swappingSlippage calculations. |
| Chains | Avalanche |
| Outcome | Partially recovered |
What happened
Platypus Finance, a stableswap automated market maker on Avalanche, lost about $2.23 million on 12 October 2023 in three flash-loan-funded transactions against its WAVAX and sAVAX pools, sent from two externally owned addresses. It was the protocol's third incident of the year, after an $8.5 million loss in February and a $157,000 loss in July.
The attacks manipulated pricing rather than bypassing authentication. CertiK's analysis describes the first attacker flash-borrowing 1.1 million WAVAX and 991,000 sAVAX, depositing them to receive Platypus LP tokens, then routing swaps between the two pools and withdrawing in a sequence that distorted each pool's cash-to-liability coverage ratio. Platypus prices swaps and slippage from that ratio, so the distortion made subsequent swaps settle in the attacker's favour; CertiK put the residue after repaying the loans at about 111,000 WAVAX, roughly $1 million, and 20,000 sAVAX, roughly $200,000. Neptune Mutual's write-up traces the same behaviour to the _quoteFrom and _swappingSlippage functions.
Crypto Times, citing CertiK, reported the three transactions individually at $1.2 million, $575,000 and $450,000. One of the attacker's contracts was left callable by others, and the security firm Supremacy used that mistake to recover about $575,000 for Platypus, which it announced publicly. Halborn gives the recovered amount as roughly $575,000 and Neptune Mutual as about $567,000, tied to a residue of 50,000 sAVAX and 7,000 AVAX, leaving around $1.6 million unrecovered.
Platypus suspended all pools while it investigated and said it would resume trading once the issues were resolved. Totals published by security firms range from about $2.2 million to $2.23 million. No arrests connected to the October incidents have been reported.
Sources
- CertiKSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Neptune MutualSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Platypus Finance (October 2023) hack — October 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/platypus-finance-october-2023https://itokenly.com/hacks/platypus-finance-october-2023Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.