Loopring Hack

REPORTED LOSS $5.0M
Medium Compromised guardian recovery service loopring

What happened

On June 9, 2024, an attacker took over 58 Loopring Smart Wallet addresses through the Official Guardian recovery service. Loopring's final report describes unauthorized changes to users' two-factor authentication records, allowing recovery codes to reach the attacker.

Technical Root Cause

Compromised 2FA records let an attacker obtain guardian approval for unauthorized wallet recovery.

Case & protocol details

Classification Infrastructure / Wallet Recovery
Protocol Type DEX
Official Website loopring.org/#/
Protocol Twitter/X @loopringorg

How it happened

1. The attacker obtained read/write access to the 2FA service and substituted their email addresses. 2.

codes were delivered to the attacker, allowing Official Guardian approval.

  1. Wallet ownership was reset and assets drained.
  2. Loopring paused affected recovery services and later added human review.

Security review history

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.