MainnetSettler Hack

Reported loss $66K
Ethereum
Token Approval Abuse

What happened

On 20 November 2024, an attacker took about $66,000 of HOLD tokens from one wallet on Ethereum. They used a token approval the victim had granted directly to 0x's Settler contract (0x70bf...4710, named MainnetSettler in the alert and PoC; Etherscan labels it "0x: Settler V1.6").

Settler is a swap-settlement contract that anyone can call, and it executes whatever list of actions the caller supplies. Victim 0xa31d...097b had approved HOLD to this contract, so any caller could make Settler call transferFrom on the HOLD token and move the victim's balance. The attacker did exactly that, taking 308,453,642 HOLD in transaction 0xfab5912f...8e9fa2. TenArmor flagged the attack and told users to revoke any approvals to the contract.

How it happened

  1. The victim wallet 0xa31d...097b had an outstanding ERC-20 approval for HOLD tokens granted to the Settler contract 0x70bf...4710.
  2. The attacker (0x3a38...f2d9) deployed an attack contract whose constructor called Settler's public execute function, with an empty slippage check and a single crafted action.
  3. That action pointed Settler at the HOLD token and carried transferFrom(victim, attacker, 308453642481581939556432141) calldata, so Settler made the call as the approved spender.
  4. Because the victim had approved Settler, the HOLD token honoured the transfer, and about 308.45M HOLD (about $66K) went straight to the attacker's address in one transaction.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.