🐳 Weekly Edition: Hacker Blunder or 4D Chess

A hacker drained $500K from a Base vault, then lost most of it to MEV seconds later. Was it a costly mistake or part of the plan?

Yesterday, a hacker drained $502,000 USDC from the Steakhouse Prime vault on Base, a yield-bearing vault. The exact attack vector hasn’t been revealed, but we know it was a phishing attack that got the victim to sign a malicious transaction draining the vault and sending the funds to the hacker’s wallet.

16 seconds after the hacker received the funds, they used a Uniswap V4 pool with thin liquidity to swap the USDC for wrapped ETH, still on Base. During the swap, they had no slippage limit and got MEVd for over $370,000. Net net, they ended up with $129,000. The funds remain in the same Base wallet.

Attack Breakdown, Source: @Kruys_Collins on X

Why would this happen? What kind of person is competent enough to hack a crypto vault but incompetent enough to lose most of it to basic MEV?

On the surface, the hacker had to move quickly because Circle, the company that controls USDC, has freeze permissions. Once an address is frozen, it can’t transfer USDC. If the attacker’s wallet was frozen, it would render the hack useless because they would have no way of cashing out of the USDC. It makes sense that they would be in a hurry to get to WETH and be willing to pay whatever was required to do it fast.

Now that the funds are in WETH on Base, they can’t be frozen by Circle. Base could theoretically halt the entire blockchain but can’t simply freeze a singular WETH address the way Circle can with USDC. There’s no world where Base would stop the blockchain over one relatively small drain, so the funds are effectively safe from that type of intervention. In spite of the fees, $129,000 is better than nothing.

The hacker had to go fast, but with some basic slippage guidelines, they could’ve walked away with much more with essentially no additional risk. You could chalk it up to nerves leading the hacker to not think clearly and accidentally forget to set slippage. You could also say it was karma for hacking. Bullies get bullied.

There’s another compelling argument that this MEV attack was a sophisticated form of money laundering. Sure, the hacker has $129,000 in WETH on Base that can’t be frozen, but the job isn’t done. Until they get it into a mixer, swap it for Monero or otherwise break the trail, it will be watched. They can’t easily sell it on a KYCd exchange, and Base DEX frontends and other service providers can blacklist the wallet. The hacker also hasn’t moved the remaining funds, so it doesn’t seem like there’s some intricate privacy plan taking shape yet.

What if the MEV attack was intentional?

The hacker could’ve created or controlled a MEV bot beforehand and set it up to sandwich their transaction the moment it hit the liquidity pool. Instead of actually losing $370,000, they effectively transferred most of the stolen value to a second wallet through what looks onchain like an unrelated MEV extraction.

Everyone thinks the hacker is an idiot, while the MEV wallet looks like an independent bot that happened to capitalize on a terrible swap. The theory would be that the MEV wallet now has a much more plausible explanation for where its funds came from, potentially making the connection to the original hack harder to establish.

There’s no blockchain evidence that the hacker wallet and the MEV wallet are connected, but that doesn’t mean much.

What do you think happened? Did the hacker get some instant karma after forgetting to set slippage on a swap, or did they just launder the funds under the veil of vigilante justice?

The Beluga intern has been hard at work gathering all the most important crypto news stories so you have them in one place!

The Majors

Alt Coins and Stocks

Crime

AI

Interesting Reads

Few know the difference.

X via @0xbags

Check out our latest content below!

Disclaimer

The content on this site is for informational purposes only and should not be construed as investment advice. While Beluga strives to ensure the accuracy and timeliness of information, there may be discrepancies when comparing our data to that of financial institutions, service providers, or specific product websites. Always consult with a professional before making any financial decisions. Will McKinnon is the Head of Content for Beluga and has spent every day for many years trading coins. For that reason there are too many to name, however his largest holdings by a significant margin are Ethereum and Bitcoin. NFA DYOR