DeFi protocol Platypus suffers second flash loan attack in 9 months

CertiK estimates the protocol has lost $1.3 million worth of wrapped AVAX and about $913,000 in liquid staked AVAX

article-image

Daniel Eskridge/Shutterstock, modified by Blockworks

share

Platypus, the Avalanche-native StableSwap protocol, suspended all of its pools on Thursday after detecting a flash loan exploit on the DeFi platform.

PeckShield, the first to report on the platform attack, disclosed on Thursday that the exploit led to losses exceeding $2 million.

Blockchain security firm CertiK laid out the results of its own investigation, saying that two attackers had taken about $1.3 million worth of wrapped AVAX (WAVAX) and about $913,000 in liquid staked AVAX (sAVAX).

Playtypus is currently investigating what went down.

Loading Tweet..

“The whole team is working & communicating with different parties to try to recover the funds from the contracts, identify the root cause of this exploit, and trace the identity of the hacker(s) right now. We will share the updates with the community soon,” a moderator wrote on the protocol’s Discord channel on Thursday.

Platypus is an automated market maker (AMM) protocol within the Avalanche blockchain, created with the primary goal of exchanging stablecoins.

The protocol raised $3.3 million in Dec. 2021 in a funding round led by now defunct crypto hedge fund Three Arrows Capital (3AC) and Defiance Capital.

The protocol suffered a separate exploit in February, losing more than $8.5 million. 

That incident was also a flash loan attack — where traders can instantaneously borrow cryptocurrencies without providing collateral and return them within the same transaction.

In that particular attack, the perpetrators exploited a vulnerability in Platypus’ native stabletoken’s USP solvency check mechanism, deceiving its smart contracts into believing that USP was completely backed.

As of September, the Platypus team recovered about 61.7% of the original losses incurred by its liquidity pools during the USP exploit. 

They tapped into a reserved treasury to initiate a second phase of compensation on Sept. 26, the team said on X.

Platypus said it would share additional updates on the latest exploit in time.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates (8).png

Research

Meta-aggregators like Titan and Kamino Swap improve price execution for users, making the Solana swapping landscape more competitive. Jupiter has incorporated meta-aggregation features into its latest routing engine to keep users on its front end (own the user, own the flow). At large, teams are treating swaps as a commoditized complement, offering incredibly cheap or free swaps to own the end-user and increase demand for high-margin product offerings (multi-product DeFi). On another note, the divergence in the concentration of aggregator volume between DEXs suggests increased specialization at the DEX layer by asset type.

article-image

Onboarding the world to Bitcoin takes a series of firsts

article-image

If we get an altcoin season, it’ll be focused on tokens deemed “ fundamentally valuable enough for traditional public money and capital” to get involved with

article-image

Solana dropped nearly 10% amid mass crypto liquidations triggered by rising geopolitical strife

article-image

Investors moved to safe assets like the US dollar and gold, but bonds faltered

article-image

The Amex offers up to 4% bitcoin back, but the deal is a bit ironic considering crypto’s goals

article-image

Short answer: Subnets are now cheaper to bootstrap than a Celestia rollup