Cook Finance's IssuanceModuleV2 exploited via oracle manipulation and thin pool seeding, draining ~$50K across three index vaults on BNB Chain.
Security & Exploits ·
Cook Finance suffered a loss of approximately $50,000 on BNB Chain following an exploit of its IssuanceModuleV2 contract. Two attackers used six transactions to drain roughly 90 BNB across three CKToken index vaults by manipulating pricing during the token issuance process.
The exploit leveraged the IssuanceModuleV2.issueWithSingleToken2() function, which mints CKToken index positions by swapping user deposits into underlying components on PancakeSwap at live spot prices without oracle safeguards or slippage protection. Attackers first seeded thin liquidity pools for the underlying assets—including ibBNB/WBNB, vBNB/WBNB, and pairs involving CAKE, MCB, XVS, DODO, and LINK—then called the issue function to mint CKToken at artificially inflated net asset values. After minting, they unwound their seeded liquidity, extracting value from the index vaults' real holdings.
The attack demonstrates a gap in Cook Finance's issuance mechanism: reliance on attacker-controlled routing and weightings combined with live spot pricing created opportunity for pool manipulation. One of the two attackers involved has been identified on-chain, though the full scope of fixes or affected users remains unannounced.