T
iTokenly

Rari Capital hack — May 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 8, 2021
Target typeOther
Loss$10,000,000Published estimates range $10,000,000 to $11,000,000Price at time of incident
MethodReentrancyRari's Ethereum Pool derived the ibETH/ETH exchange rate itself from ibETH.totalETH() divided by ibETH.totalSupply(). Using 59,000 ETH flash-borrowed from dYdX, the attacker deposited into the pool at the normal rate to mint REPT shares, then called Alpha Homora's work(), which permitted a caller to execute arbitrary contract calls inside it, so that a fake token contract's malicious safeApprove() transferred 2,000 ETH into the ibETH Bank contract and temporarily inflated totalETH(). Re-entering Rari from inside that call, the attacker withdrew the full 59,000 ETH while burning fewer REPT than had been minted, leaving a surplus of roughly 30 REPT. The flash loan was repaid and the surplus shares were redeemed for ETH in a follow-up transaction once the rate normalised.
ChainsEthereum
OutcomeUsers reimbursed

What happened

Rari Capital's Ethereum Pool was drained on 8 May 2021. Rari's own post-mortem says an attacker took approximately 2,600 ETH, around $10 million, amounting to 60% of all user funds in that pool. CoinDesk valued the same 2,600 ETH at about $10.6 million and Halborn's analysis at roughly $11 million; the spread comes from which ETH price is applied, not from any dispute over the quantity of ETH.

The pool allocated part of its ETH to Alpha Homora's interest-bearing ibETH token, and derived the ibETH/ETH rate itself by dividing ibETH.totalETH() by ibETH.totalSupply(). Alpha Homora's work() function permitted a caller to execute arbitrary contract calls inside it. Using 59,000 ETH flash-borrowed from dYdX, the attacker first deposited into the Rari pool at the ordinary rate to mint pool shares, then called work() with encoded data so that a fake token contract's malicious safeApprove() pushed 2,000 ETH into the ibETH Bank contract, temporarily inflating totalETH(). Re-entering Rari from inside that call, the attacker withdrew the full 59,000 ETH while burning fewer shares than had been minted, leaving a surplus of roughly 30 shares. The flash loan was repaid and the surplus was redeemed for ETH in a follow-up transaction after the rate normalised.

One published timeline puts the first exploit transaction at 13:48 UTC with the pool paused at 14:34 UTC, protecting roughly a further $6 million, and notes that the exploiting address had been used a day earlier against Value DeFi's vSafe vault on BNB Chain. Rari's post-mortem locates the flaw in how its own pool computed the ibETH exchange rate.

Rari's contributors returned 2 million RGT that had been allocated to them from the developer fund, asking that it be used to reimburse depositors who lost funds. RGT fell from more than $17 before the exploit to about $9.07, close to a 50% drop, before rebounding. No arrest or identification of the attacker has been reported.

Sources

  1. Rari CapitalPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01
  4. Nipun Pitimanaaree (independent timeline analysis)Secondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/rari-capital/5-8-2021-rari-ethereum-pool-post-mortem-60aab6a6f8f9

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Rari Capital hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/rari-capital
https://itokenly.com/hacks/rari-capital

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.