Drips Network Hack
What happened
On July 14, 2026, a legacy Ethereum DaiDripsHub deployment was exploited for approximately 24,883 DAI. The transaction drained the protocol's recorded DAI reserve in a single call.
The legacy DaiDripsHub used an unchecked uint128-to-int128 conversion to encode transfer direction in -int128(amt), without requiring the input to fit the positive int128 range.
How it happened
The attacker supplied a crafted uint128 amount to give(). When the contract converted that value to int128 and negated it, the sign reversal selected the reserve-withdrawal branch instead of the intended deposit path, sending the reserve balance to the attacker contract.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.