Loopring Hack
What happened
On June 9, 2024, an attacker took over 58 Loopring Smart Wallet addresses through the Official Guardian recovery service. Loopring's final report describes unauthorized changes to users' two-factor authentication records, allowing recovery codes to reach the attacker.
Compromised 2FA records let an attacker obtain guardian approval for unauthorized wallet recovery.
Case & protocol details
How it happened
1. The attacker obtained read/write access to the 2FA service and substituted their email addresses. 2.
codes were delivered to the attacker, allowing Official Guardian approval.
- Wallet ownership was reset and assets drained.
- Loopring paused affected recovery services and later added human review.
Security review history
- SECBIT Labs Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.