Zabu Finance hack — September 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 12, 2021 |
| Target type | Other |
| Loss | $3,200,000Price at time of incident |
| Method | Contract logic errorThe ZABUFarm staking contract recorded the amount a user declared they were staking rather than the smaller amount actually received after SPORE's transfer fee was deducted. Repeated deposit and withdrawal cycles therefore returned more SPORE than had been supplied, draining the contract; once its balance neared zero the reward formula returned an inflated per-token figure, which was used to mint the remaining ZABU reward pool. SPORE flash-borrowed from Pangolin was used to run the cycle at scale. |
| Chains | Avalanche |
| Outcome | Unresolved |
What happened
On 12 September 2021 an attacker drained the staking contract of Zabu Finance, a yield farm on Avalanche. CoinDesk, citing analytics provider DeFiprime, described it as an estimated $3.2 million loss and probably the first large exploit on that chain.
The flaw was in how the ZABUFarm contract accounted for SPORE, a token that charges a fee on every transfer and redistributes it to holders. Halborn's analysis found the farm recorded the amount a user said they were staking rather than the smaller amount that actually arrived after the fee, so each deposit and withdrawal cycle returned more SPORE than had been supplied and steadily emptied the contract. Once its SPORE balance was near zero, the reward formula, which divides accumulated block rewards by the tokens staked, returned an inflated figure, and the attacker used that to mint the remaining reward pool. Knownsec Blockchain Lab's write-up describes two attacker contracts and the use of SPORE flash-borrowed from Pangolin to run the cycle at scale.
About 4.5 billion ZABU were taken and dumped on Trader Joe and Pangolin, driving the price from roughly $0.0047 to near zero. How the $3.2 million estimate was derived is not shown in the sources: 4.5 billion tokens at the pre-attack price would be a much larger notional sum, and the price collapsed as the tokens were sold, so what the attacker actually realised is not established.
Zabu said it would take a snapshot from immediately before the exploit to separate holders who bought before the attack from those who bought after, and discussed reissuing tokens. No completed compensation or recovery has been documented. Halborn notes the same fee-on-transfer accounting bug had hit PolyYeld Finance two months earlier.
Sources
- HalbornSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- Knownsec Blockchain LabSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Zabu Finance hack — September 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/zabu-financehttps://itokenly.com/hacks/zabu-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.