DEUS Finance Hack

TOTAL LOST $6.5M
Medium Burn Function Mistake / Other arbitrum bsc ethereum

Summarize with AI

Affected Chain arbitrum 3 chains affected
Recovered - No recovery reported
All-Time Rank #383 By amount stolen
Auditors 1 Prior security audit

Incident Overview

Deus Finance was exploited due to a logic flaw in the $DEI token contract. The attacker drained pools on both Arbitrum and Binance Smart Chain (BSC) chains resulting in a loss of 6,227,977 $USD.

DEI is a stablecoin of Deus Finance which lost its dollar peg on the previous hack. On May 5th, 2023 Deus Finance's $DEI token was exploited due to a logic flaw related to burn issue that allowed an attacker to drain DEI/USD and DEI/USDC pools on both Arbitrum and Binance Smart Chain (BSC) chains. The attacker performed zero-amount burns and received $DEI tokens for nothing, which was consequently swapped for valuable stablecoins. On BSC chain alone roughly 1,336,814 $USD was lost. The stolen funds were transferred through several EOA addresses and then swapped for $DAI. And 4,891,163 $USD were drained from the Arbitrum chain and swapped for 2,529 $ETH, which remain at the same address.

The attack resulted in a total loss of approximately 6,227,977 $USD worth of crypto assets from both chains combined.

Attacker initial address in BSC: https://bscscan.com/address/0x08e80ecb…98f599

Funds holder address in BSC: https://bscscan.com/address/0xdf610228…9cb465

Malicious transaction in Binance Smart Chain: https://bscscan.com/tx/0xde2c8718…a190c3

Attacker initial address in the Arbitrum chain: https://arbiscan.io/address/0x189cf534…b122d1

Malicious transaction in the Arbitrum chain: https://arbiscan.io/tx/0xb1141785…3c37ef

Incident Report

Protocol / Project DEUS Finance
Date of Incident
Affected Chain(s) arbitrum bsc ethereum
Attack Technique Burn Function Mistake / Other
Classification Protocol Logic / Stablecoin
Primary Source View Post-Mortem

Protocol Information

Protocol Type CDP
Affected Token DEI
Smart Contract Language Solidity
Official Website deus.finance/
Protocol Twitter/X @DeusDao
Team Public / Doxxed
Source Code Verified On-Chain

Market Context at Time of Hack

Token Categories
Ethereum Ecosystem Polygon Ecosystem Fantom Ecosystem BNB Chain Ecosystem Base Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of burn function mistake / other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with arbitrum, bsc, ethereum smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in DEUS Finance's contract logic - root cause: protocol logic / stablecoin
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Burn Function Mistake / Other audit checklist and test coverage
Audited by Certik — still lost $6.5M. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to DEUS Finance, these are the critical security checks that could have prevented this incident (May 2023).

  • Verify all logic paths related to Burn Function Mistake / Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Security Audit History

Bug Bounty Immunefi Details

Sources & References

Learn to Prevent the Next DEUS Finance

The DEUS Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial