Loopscale Hack
What happened
On April 26, 2025, Loopscale was exploited due to a pricing system vulnerability, resulting in the loss of approximately 39,474 SOL (~$5.8M), though over $2.8M has since been returned.
The attacker exploited a flaw in Loopscale’s pricing mechanism, enabling them to manipulate loan conditions and extract funds from the SOL and USDC Genesis Vaults. In response, the Loopscale team temporarily suspended most app functions while investigating the breach and coordinating with security partners and law enforcement. A message was sent directly to the exploiter, offering a whitehat agreement: return 90% of the stolen funds (35,527 SOL) in exchange for keeping a 10% bounty (3,947 SOL) and exemption from liability.
As of April 27, the exploiter returned a total of 19,463 WSOL (~$2.88M), with funds delivered across multiple transactions. Law enforcement, exchanges, and bridge protocols have been alerted, and further legal steps are pending if no agreement is reached. A full post-mortem is in progress.
Case & protocol details
Funds Recovery
Recovered
$2.9M
Net Loss
$2,917,400
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.