ChainBleedv0.1 · open intel
← back to feed·AVAXFLASHLOAN2021-09-12 · 4y ago
Incident · SLOWMIST

Zabu Finance

Contract Vulnerability
Estimated loss
$3.20M
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
FLASHLOAN
FLASHLOANBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2021-09/ZABU_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

The Zabu Finance project on the Avalanche chain suffered a flash loan attack. Officially, the attackers withdrew 4.5 billion ZABU tokens from the Zabu Farm Contract, bringing the supply to 5 billion and dumping all of it to ZABU’s Pangolin LPs and Trader Joe LPs. According to DeFi analytics provider DeFiprime, the total was estimated at $3.2 million in exploits. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 3,200,000.

Primary source
https://www.coindesk.com/tech/2021/09/13/avalanche-based-zabu-finance-exploited-in-32m-hack/
Sourced from
slowmist
Technical record
chain
avalanche
protocol
Zabu Finance
bug_class
flashloan
date_occurred
2021-09-12
loss_usd
$3,200,000
source_id
sm:zabu-finance::2021-09-12
Related — same bug class· flashloan
2026-05-11
1mo ago
POLY
Ink Finance
Contract Vulnerability
flashloan
$140.0K
UNRATED
2026-05-04
1mo ago
ETH
SmartCredit
Flashloan Exploit
flashloan
$72.0K
UNRATED
2026-05-04
1mo ago
SmartCredit
Flash Loan Exploit
flashloan
$72.0K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Flashloan Exploit
flashloan
$228.0K
UNRATED
2026-04-28
1mo ago
JUDAO
Exploit
flashloan
$228.0K
UNRATED
2026-04-15
1mo ago
LootBot AI
Contract Vulnerability
flashloan
$9.6K
UNRATED
ChainBleed — live web3 threat intelligence