DODO AMM Hack
What happened
On 8 March 2021 UTC, a flaw in DODO V2 Crowdpooling let an attacker reconfigure affected pools during a flash-loan-funded transaction. The WSZO, WCRES, ETHA, and FUSI Crowdpools were affected; DODO's trading module, V1 pools, and other V2 pools were not. DODO estimated the gross loss at about $3.8 million in USDT, ETH, and project tokens.
The root cause was an authorization and repeated-initialization defect, not a failure of flash lending itself. DODO later reported $3.1 million returned within 24 hours; that is separate from the gross-loss figure.
DODO V2 Crowdpool init() did not enforce a one-time, authorized initialization invariant. Reinitialization during the flash-loan path let attacker-controlled counterfeit tokens replace the tracked pair and defeat the repayment check.
How it happened
- The attacker prepared counterfeit tokens and used flash-borrowed assets to interact with a vulnerable V2 Crowdpool.
- Its init() path could be called more than once, allowing the pool's tracked token pair to be replaced during the transaction.
- The attacker then used sync() and the reinitialized state so the repayment check no longer reflected the genuine assets that had been borrowed.
- That let real pool assets leave while the counterfeit-token state made the loan path appear settled.
- Mempool bots copied and front-ran parts of the sequence; their later returns helped recover much of the value but did not remove the original authorization flaw.
Protocol details
Security review history
- SlowMist View report
- PeckShield View report
- CertiK View report
- Beosin View report
Funds Recovery
Recovered
$3.1M
Net Loss
$699,200
Evidence
Proof of concept
1 availableSources
- report DODO Pool Incident Postmortem blog.dodoex.io
- report Post-mortem rekt.news
- transaction Primary exploit transaction etherscan.io
- analysis Website reference halborn.com
- analysis Support reference dodoexhelp.zendesk.com
- analysis DeFiLlama defillama.com
- analysis DODO DEX exploit analysis halborn.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.