Rapid Insights: Analyzing Ankr's Liquid-Staking Protocol Infinite Mint Exploit

DeFi ProtocolsDecember 3, 2022, 7:31PM EST
UPDATED: April 14, 2023, 4:19PM EDT
Rapid Insights: Analyzing Ankr's Liquid-Staking Protocol Infinite Mint Exploit
Partner offers

We'd love your feedback.

Advertisement

The Ankr protocol has become the latest victim in a major exploit late on December 1st that left its premier liquid-staked derivative (LSD) for the BNB Chain ecosystem, aBNBc, with an extremely inflated supply and only a fraction of its original value. In the BNB Chain ecosystem, Ankr offers two LSD options for staking BNB: aBNBb and aBNBc. The former is a “reward earning” rebasing token, whose supply increases gradually over time to reflect earnings from staking and whose value remains pegged 1:1 to native BNB. The latter is a “reward bearing” token whose value increases over time as staking rewards are accumulated but whose supply only changes when additional BNB is staked or unstaked. Both of these LSD options are effectively receipts for BNB staked by users to validators, and aBNBc can be thought of as simply a wrapper for aBNBb that makes it easier to be used in other protocols. 

The exploit first kicked off on December 1st, 2022, at 7:43 PM EST with a transaction upgrading the implementation for the aBNBc smart contract. A few moments later, the Ankr deployer was manipulated to mint 10 trillion new aBNBc tokens to the exploiter’s address, effectively rendering the existing supply of aBNBc worthless. It is important to note that these initial transactions are only executable via the Ankr deployer, which means that a private key compromise is the most plausible explanation for the attack. 

Expert insights. Delivered.

Get access to a suite of news, research, data, and funding tools