There was a MEV recently that was sandwiching millions over the year, someone made a contract to trick it buy and click approve, then sucked all his liq.
QUOTE ON THIS
Zero pity.
The notorious MEV bot known as
0xbad has fallen on hard times, just like the rest of us.
After 75 days of exploiting value from unexpecting users, this mempool menace backfired on its owner, creating a beautiful display of on-chain karma.
After one unfortunate user tried to
swap $1.85M of Compound cUSDC for USDC on Uniswap v2, a lack of liquidity meant they only received $500 in USDC. 0xbad was quick to profit from the swap, backrunning the trade with an
elaborate arb involving many different DeFi dApps.
$1.02M profit.
Nice.
However…
0xbad got put down… tremendously.
An anonymous attacker noticed a flaw in the bots arbitrage contract code, and
stole not only the recently acquired 800 ETH, but the entire 1,101 ETH in 0xbad’s wallet.
Attacker’s address: 0xb9f78307ded12112c1f09c16009e03ef4ef16612
0xbad: 0xbadc0defafcf6d4239bdf0b66da4d7bd36fcf05a
bertcmiller of Flashbots broke it down:
0xbad did not properly protect the function that they used to execute the dYdX flashloans.
Note "callFunction," which is the function called by the dYdX router as a part of flashloan execution
When you get a flashloan the protocol you're borrowing from will call a standardized function on your contract.
In this case dYdX called "callFunction" on 0xbad.
Unfortunately for 0xbad, their code allowed for arbitrary execution.
The attacker used this to get 0xbad to
approve all of their WETH for spender on their contract.
The attacker then simply
transferred the WETH out to their address.
Down 0xbad
To add further drama to the drama, 0xbad decided to try and threaten their attacker with a message sent via transaction input data.
Then came
a reply:
Last year, in “Return to the Dark Forest”, we wrote:
But not this time…
MEV bots act on the boundary of “code is law”.
In the PvP arena that is Ethereum’s Dark Forest, sometimes you win and sometimes you lose.
Despite the fact that the funds were never returned to their original owner, it’s nice to see such a prompt display of on-chain karma.
As Bert Miller wrote on Twitter:
Bad code, great content
Hilarious!