FixedTokenBSwap Hack

Reported loss $2K
Ethereum
Spot Price Manipulation

What happened

A token-swap contract called FixedTokenBSwap on Ethereum was drained of 500 RTV tokens on June 15, 2025, valued at about $2,200 when the alert fired. Its swap() function paid out a fixed 10 RTV per swap, once per address per day. It accepted any caller-supplied token path, priced the payment with Uniswap V2 getAmountsIn, and collected it with a plain transferFrom.

The attacker deployed a fake token whose transferFrom did nothing and seeded a new fake-token/RTV Uniswap pair to serve as the price source. Fifty freshly deployed helper contracts then each claimed 10 RTV for free, which got around the daily limit. The whole attack ran inside the constructor of a single contract, which is why Defimon flagged it as an "exploit in initcode".

The attacker sold 490 of the RTV for about 0.44 ETH (roughly $1,100 at the time) and kept 10 RTV.

How it happened

  1. The attacker's contract constructor swapped 0.01 ETH for RTV on Uniswap V2.
  2. It deployed a fake token whose balanceOf always returns 100 tokens and whose transfer/transferFrom return true without moving anything. It created a fake-token/RTV Uniswap V2 pair, sent it the RTV and called sync(), so the pair could quote a price for the fake token.
  3. It deployed 50 helper contracts. Each called FixedTokenBSwap.swap([fakeToken, RTV], type(uint256).max). The victim priced the input through getAmountsIn on the attacker's pair, called the fake token's no-op transferFrom as payment, and sent the helper 10 real RTV.
  4. Each helper passed its RTV back and self-destructed, so a new address was used every time and the one-swap-per-day check never triggered.
  5. The attacker sold 490 of the 500 RTV for 0.440427 ETH on Uniswap V2 and kept the remaining 10. After the 0.01 ETH seed, 0.430427 ETH was sent to the attacker's address.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.