CryptoReal
CASE FILE — Dec 29, 2020

Infinite-Mint Bug at Cover Protocol Ends With a Self-Styled "White Hat" Rescue

An infinite-mint vulnerability in Cover Protocol's shield-mining contract let attackers create COVER tokens out of nothing, inflating the total supply by roughly 48 quadrillion percent — from 84,477 tokens to 40,796,131,214,802,600,000 — before the loophole was closed. COVER's price (the token was previously called SAFE) collapsed by around 90% in the aftermath.

Of the roughly $9.4 million taken across the incident, about $3.2 million was later recovered, leaving net losses of around $6.2 million. Six separate addresses used the exploit to mint tokens before it was patched; some of those actors kept the proceeds, while others returned funds.

The most attention went not to the original attacker but to a previously obscure entity called Grap Finance, which used the same loophole to mint and sell COVER for ETH, then framed the episode as a "white hat" rescue — returning funds along with a pointed public message. As with much of DeFi, motives and outcomes were rarely as clean as they first appeared, since anonymity and composability leave room for multiple parties to profit differently from the same incident.

Sequence of events

The original exploit sequence involved four steps carried out by a single attacker, before the method was shared publicly and replicated by other wallets. The timeline below is drawn from Cover's own post-mortem writeup; a more granular technical walkthrough is available from @vasa_dev.

First exploiter's timeline (all times UTC, December 28, 2020):

In total, this first exploiter is estimated to have taken about $4.4 million in user funds, moved to this address. Notably, the wallet's operational security was weak — it was a standard, KYC'd wallet funded by an exchange with roughly three years of trading history, suggesting the loophole may have been found somewhat by accident. Some observers claimed to know the exploiter's identity and publicly urged that the funds be returned.

Grap Finance's parallel run

Once the first exploit drew comparatively little attention, Grap Finance's use of the same bug — recast as a "white hat" rescue — became the more prominent storyline.

Grap Finance's timeline (all times UTC, December 28, 2020):

  • 11:54:47Grap Finance's deployer address deposited 15,255.552810089260015362 BPT from the DAI/Basis pool into the Blacksmith farming contract.
  • 11:58:04 — The same deployer address withdrew 15,255.552810089260015361 BPT from the DAI/Basis pool, leaving a balance of just 1 wei in the Blacksmith contract.
  • 11:58:56A separate user withdrew nearly all of their own balance (1,007.599009946121991627 BPT), leaving Grap Finance as the sole holder of DAI/Basis pool liquidity in the shield-mining Blacksmith contract — amounting to exactly 1 wei.
  • 12:00:21 — Grap Finance's deployer redeposited 15,255.552810089260015361 BPT from the DAI/Basis pool into the Blacksmith contract.
  • 12:02:04 — Grap Finance's deployer claimed rewards; the combination of a 1-wei balance with an underlying storage/memory bug triggered the minting of 40,796,131,214,802,500,000.212114436030863813 COVER tokens.
  • 12:29:03 — Grap Finance's deployer began selling as much of the minted supply as possible across multiple transactions via 1inch.exchange.
  • 12:59:27 — Grap Finance's deployer burned the remaining minted tokens.
  • 13:41:01 — Grap Finance's deployer transferred 4,351 ETH (made up of 1 ETH plus 4,350 ETH) extracted from selling COVER, sending it all to the deployer account. This sum represents about 34% of the total $9.4 million in exploit damage.
Sums referenced in this case file

Cover Protocol's response

It took roughly six hours after the attack began for Cover Protocol to publicly acknowledge it, stating:

The team is still investigating the current incident. The exploit is no longer possible.

Please do NOT buy $COVER tokens, and remove your liquidity from the COVER/ETH pool on sushiswap.

CLAIM/NOCLAIM balancer pools are unaffected.

Roughly eight hours after the attack, the team announced plans to make affected users whole:

Hello everyone, we are exploring providing a NEW $COVER token through a snapshot before the minting exploit was abused. The 4350 ETH that has been returned by the attacker will also be handled through a snapshot to the LP token holders. We are still investigating. Do NOT buy COVER.

This would mark a fourth iteration of the project's token, following its path from SAFE to SAFE2 to COVER — with a new, as-yet-unnamed replacement (referred to informally as "$RECOVER") now planned. The project had previously rebranded from SAFE after issues involving both @azeemfi and @chefcoverage, migrating first to SAFE2 and later to the COVER token affected in this incident.

The Grap Finance narrative

Grap Finance is itself a fork of YAM. Having not shipped anything notable during the prior "DeFi summer," the project used its role in the COVER incident to build an audience, gaining thousands of followers within a single day by presenting its actions as a white-hat rescue. Its unusual transaction activity placed it among the top five balance changes for COVER over the preceding seven days.

The day of the attack also saw a spike in COVER's unique address count, up by 1,778, as speculative traders attempted to trade the falling token. Exchange data showed Binance recording a sharp increase in COVER deposits as holders looked to exit before trading was eventually paused. Meanwhile, the token GRAP — associated with Grap Finance — saw its price climb sharply, with commentators noting the mismatch between the modest actual recovery and the outsized attention Grap received.

Speculation also circulated that the incident may have involved an insider, with one theory suggesting the attacker(s) were identified privately, could not safely keep the funds, returned them, and instead profited from the resulting publicity. These theories are unverified rumors, not established fact, but they gained some plausibility after moves such as an MXC exchange announcement listing a related token seemingly on the basis of the unfolding story. The GRAP token's price rose by several thousand percent, with its 24-hour trading volume increasing from $236 to $5,458,084 at the time of the original report.

Community reaction

Emiliano Bonassi offered the following comment on the incident:

Setting aside the technical issue, this event showed again how this ecosystem is cohesive and supportive.

We are antifragile.

I am pretty sure that after this event not only a new Cover will emerge but more importantly a collective to guarantee safety and prompt reaction in the ecosystem - maybe The WhiteHack Group.

Broader context

The incident adds to a rough stretch for DeFi insurance protocols, following a separate incident at NXM. Regardless of whether a protocol's own funds are technically unaffected, user confidence tends to erode once an incident becomes public. COVER's price fell roughly 40x within four hours of the exploit, even as GRAP's price rose by a comparable multiple over the same stretch. Grap Finance's own public statement claimed "no gains" from the episode — an account that, per the reporting above, appears only partially complete.

cover
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.