Counterexploit Salvages Stolen Funds From Platypus Hacker

After the initial hack, Platypus updated its pool contract to counterexploit $2.4 million in USDC from the hacker

article-image

DALL-E modified by Blockworks

share

Platypus, a DeFi stablecoin swapping protocol on Avalanche, was exploited for $8.5 million on Thursday evening.

The exploit occurred via a flashloan attack that took advantage of a flaw in its USP solvency check mechanism — which tricked Platypus’s smart contracts into thinking that USP was fully backed. USP is Platypus’ native stabletoken. 

Soon after the exploit, crypto community members came together to recover the funds. 

ZachXBT — a crypto scam researcher — said on Twitter that he tracked down the attacker’s wallet address after reviewing their own chain history across multiple chains.

“Your OpenSea account links directly to your Twitter and you liked a Tweet about the Platypus exploit,” ZachXBT tweeted.

Loading Tweet..

“We’d like to negotiate returning of the funds before we engage with law enforcement,” he wrote.

Platypus — meanwhile and with the help of BlockSec — updated its pool contract to counterexploit $2.4 million in USDC from the hacker.

“They updated it such that when the exploit contract deposited the USDC (which it is tricked to believe is a flash loan) as collateral for the minting of USP, they could trick the code that it owed 0 USDC back,” Twitter user nervoir said.

The USDC from the fake pool was sent to hardcoded addresses to avoid generalized front runners, nervoir tweeted. 

“The other assets will probably be harder to recover but given that they control the pool code they have significant control,” they said.

Loading Tweet..

Platypus’s stablecoin, USP, lost its peg to the dollar, dropping to $0.48. It then briefly recovered to $0.97, but has since dipped back down to $0.48, data from CoinGecko shows.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (2).png

Research

This reports analyzes the competitive dynamics of the Solana DEX landscape, identifying sustainable moats per protocol. We also find that Raydium (RAY), Orca (ORCA), and Lifinity (LFNTY) are valued very similarly on a P/S basis and what this could mean for Meteroa's (MET) valuation, which is still pre-TGE.

article-image

Accepting change is hard, but maybe we’ll never actually get to run back 2021

article-image

As Solana’s tech matures, some founders are starting new businesses based on old ideas that weren’t formerly feasible

article-image

History suggests tariff threat-fueled trade war fears often pass as quickly as they form, analyst Matt Britzman noted

article-image

Many look to Bloomberg Intelligence analysts James Seyffart and Eric Balchunas for credibility regarding ETF approvals

article-image

AI platform Kaito’s tweet-to-earn leaderboard gives users points for posting about crypto

article-image

Lido’s new BORG Foundation aims to strengthen governance and institutional adoption