{"investigation":{"slug":"moonhacker","entity_name":"MoonHacker","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"MoonHacker is an independently deployed DeFi vault protocol built on Optimism that was designed to interact with the Moonwell lending protocol. On December 23, 2024, MoonHacker vault contracts suffered a flash loan exploit due to improper input validation and absent access controls in the executeOperation function, resulting in the loss of approximately $320,000 USDC. The Moonwell team confirmed no affiliation with MoonHacker, the vault deployers remain anonymous, and stolen funds were converted to DAI and routed through Tornado Cash, complicating recovery efforts.","sections":[{"content":"MoonHacker is a DeFi vault protocol deployed on the Optimism network. Its vault contracts were designed to interact with Moonwell, an open-source lending and borrowing protocol, to offer users automated yield strategies. Moonwell DeFi has publicly clarified that MoonHacker vaults were independently deployed by third-party developers and are not affiliated with or endorsed by the Moonwell protocol or its team. The vault deployers' identities remain unknown. No official website, documentation, or team disclosures have been independently verified as of the date of this investigation. The protocol had no publicly acknowledged audit record prior to the exploit incident.","heading":"Protocol Overview","sources":[{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/moonhacker-vault-hack-analysis","name":"blog.verichains.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 23, 2024, MoonHacker vault contracts were exploited through a combination of an unchecked flash loan callback and an unrestricted approve proxy, as characterized by security firm Dedaub. The root cause was improper input validation and lack of access control in the vault's executeOperation function. The mToken parameter accepted by the function was not validated against a whitelist of legitimate Moonwell market contracts. This allowed the attacker to supply a malicious contract address as the mToken argument. The function then granted the attacker's contract unlimited approval to transfer USDC tokens held in the vault. Using that approval, the attacker drained the vault's USDC holdings. The complete attack flow involved: (1) receiving initial funding via Tornado Cash on Ethereum; (2) executing a flash loan of USDC from Aave on Optimism; (3) passing a malicious contract as the mToken parameter in executeOperation to obtain token approvals; (4) calling repayBorrow and redeem functions repeatedly to withdraw the underlying USDC; and (5) repaying the flash loan and retaining approximately $320,000 USDC in profit. Dedaub noted that their automated monitoring tools had flagged the vulnerabilities — specifically the unchecked flashloan callback and unrestricted approve proxy — with high confidence in the days before the exploit occurred, but no remediation took place.","heading":"December 2024 Exploit — Flash Loan and Logic Vulnerability","sources":[{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/moonhacker-vault-hack-analysis","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://x.com/dedaub/status/1874838342485102852","name":"x.com","type":"other","credibility":3},{"url":"https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","name":"coinedition.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker's wallet address is 0x36491840ebcf040413003df9fb65b6bc9a181f52. The primary attack transaction hash is 0xd12016b25d7aef681ade3dc3c9d1a1cc12f35b2c99953ff0e0ee23a59454c4fe on Optimism. Two malicious exploit contracts were deployed by the attacker, identified at 0x4E258... and 0x3a6ea... on Optimism. The vulnerable MoonHacker vault contract address is 0xd9b45e2c389b6ad55dd3631abc1de6f2d2229847. Following the exploit, approximately $320,000 in USDC was swapped for DAI, which remained in the attacker's wallet at the time of initial reporting. The attacker's wallet was pre-funded through Tornado Cash on the Ethereum mainnet prior to the attack, which security analysts noted is a common pattern used to obscure the attacker's identity and complicate tracing. No funds had been recovered as of reporting.","heading":"On-Chain Forensics and Fund Movement","sources":[{"url":"https://blog.verichains.io/p/moonhacker-vault-hack-analysis","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2158930","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","name":"bitcoinethereumnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"No publicly verifiable audit of the MoonHacker vault contracts by a recognized smart contract security firm has been identified prior to the December 2024 exploit. Security firm Dedaub stated that their monitoring infrastructure had flagged the critical vulnerabilities — specifically an unchecked flash loan callback and an unrestricted approve proxy — with high confidence in the days before the attack. The absence of any remediation action following these pre-exploit flags indicates that either the warnings were not acted upon or were not surfaced to parties who could respond. The SolidityScan post-mortem analysis identified the missing input validation on the mToken parameter and the absent access controls on executeOperation as the two core flaws. Both are considered standard security requirements in DeFi vault design and are addressed in widely available auditing frameworks. The Verichains post-mortem similarly cited these issues and recommended that developers validate contract addresses against whitelists and implement proper access controls to prevent similar exploits.","heading":"Security Posture and Audit History","sources":[{"url":"https://x.com/dedaub/status/1874838342485102852","name":"x.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/moonhacker-vault-hack-analysis","name":"blog.verichains.io","type":"other","credibility":3}],"severity":"medium"},{"content":"As of reporting following the exploit, the Moonwell team stated it had no affiliation with MoonHacker and that both the vault deployers and the attacker were unknown to them. The MoonHacker vault deployers had been contacted in an attempt to address the vulnerability and coordinate recovery, though no outcome was publicly confirmed. No official incident response statement from a named MoonHacker team member was published. No user reimbursement plan was announced. The deployers and any controlling parties behind the MoonHacker vaults remain anonymous as of available public records. The combination of anonymous operators, unaudited contracts, pre-exploit vulnerability flags that went unaddressed, and the use of Tornado Cash to obscure the attacker's funding source are risk factors noted by security analysts reviewing the incident.","heading":"Team Response and Anonymity","sources":[{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","name":"coinedition.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","name":"bitcoinethereumnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"MoonHacker has been flagged by ZachXBT, the pseudonymous blockchain investigator known for tracking DeFi exploits, scams, and illicit fund flows. The specific nature or timing of ZachXBT's flag has not been independently sourced from a verifiable public post or report as of the date of this investigation. Security monitoring firm Cyvers Alerts issued alerts about the attack on Moonwell's USDC lending contract on Optimism at the time of the exploit, noting that attackers deployed malicious mToken contracts to obtain unauthorized approvals from MoonHacker vault contracts. The incident was also catalogued by the BlockThreat security newsletter in its Week 52, 2024 issue. The incident is representative of a broader pattern of exploits targeting unaudited third-party vault protocols that wrap audited underlying protocols, where security assumptions about the underlying protocol do not extend to the wrapper.","heading":"ZachXBT Flag and Broader Context","sources":[{"url":"https://newsletter.blockthreat.io/p/blockthreat-week-52-2024","name":"newsletter.blockthreat.io","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2158930","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-12-23","event":"MoonHacker vault contracts exploited on Optimism via flash loan and unchecked executeOperation callback; approximately $320,000 USDC drained.","source":""},{"date":"2024-12-23","event":"Cyvers Alerts issues real-time alert identifying the attack on Moonwell's USDC lending contract on Optimism involving MoonHacker vault contracts.","source":""},{"date":"2024-12-23","event":"Stolen USDC swapped to DAI and retained in attacker wallet; attacker wallet had been pre-funded via Tornado Cash on Ethereum.","source":""},{"date":"2024-12-24","event":"Moonwell DeFi publicly disavows any affiliation with MoonHacker, confirming core Moonwell lending pools are unaffected.","source":""},{"date":"2025-01-02","event":"Dedaub discloses on X that its monitoring tools had flagged the unchecked flashloan callback and unrestricted approve proxy vulnerabilities in MoonHacker with high confidence prior to the exploit.","source":""}],"sources_used":[{"url":"https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20260819125306/https://blog.solidityscan.com/moonhacker-vault-hack-analysis-ab122cb226f6/","credibility":3,"archive_timestamp":"2026-08-19T12:53:06+00:00"},{"url":"https://blog.verichains.io/p/moonhacker-vault-hack-analysis","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260608060940/https://blog.verichains.io/p/moonhacker-vault-hack-analysis","credibility":3,"archive_timestamp":"2026-06-08T06:09:40+00:00"},{"url":"https://x.com/dedaub/status/1874838342485102852","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","name":"coinedition.com","type":"other","archive_url":"https://web.archive.org/web/20260829225151/https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","credibility":3,"archive_timestamp":"2026-08-29T22:51:51+00:00"},{"url":"https://www.chaincatcher.com/en/article/2158930","name":"chaincatcher.com","type":"other","archive_url":"https://web.archive.org/web/20260829044624/https://www.chaincatcher.com/en/article/2158930","credibility":3,"archive_timestamp":"2026-08-29T04:46:24+00:00"},{"url":"https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","name":"bitcoinethereumnews.com","type":"other","archive_url":"http://web.archive.org/web/20260829023902/https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","credibility":3,"archive_timestamp":"2026-08-29T02:39:02+00:00"},{"url":"https://newsletter.blockthreat.io/p/blockthreat-week-52-2024","name":"newsletter.blockthreat.io","type":"other","archive_url":"http://web.archive.org/web/20251214010858/https://newsletter.blockthreat.io/p/blockthreat-week-52-2024","credibility":3,"archive_timestamp":"2025-12-14T01:08:58+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:26.590717+00:00","updated_at":"2026-08-29T23:26:13.319367+00:00"}}