Concentric Hack
Approximate loss
$1.9M
Compromised vault-upgrade authority
What happened
On January 22, 2024, a compromised Concentric administrator wallet enabled malicious vault upgrades. CertiK calculated approximately $1.85 million in losses, including tokens taken from users who had granted spending approvals.
Technical root cause
Compromised upgrade authority allowed malicious vault implementations to seize vault assets and approved user tokens.
How it happened
- The attacker used the compromised deployer wallet to transfer contract ownership.
- The new owner upgraded pool contracts with malicious code.
- Calls to
adminMint()andburn()converted manipulated CONE-1 balances into vault assets. - A second malicious contract took tokens covered by users' existing approvals.
Protocol details
Classification
Infrastructure / Yield Aggregator / Social Engineering
Protocol Type
Exploit/Access control
Affected asset / contract
CONE
Implementation language
Solidity
Protocol links
Website
@ConcentricFi
Evidence
- report @ConcentricFi incident report twitter.com
- analysis Web Archive archive.ph
- analysis DeFiLlama defillama.com
- analysis Concentric.Fi Incident Analysis certik.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.