MainnetSettler Hack
What happened
On 20 November 2024, an attacker took about $66,000 of HOLD tokens from one wallet on Ethereum. They used a token approval the victim had granted directly to 0x's Settler contract (0x70bf...4710, named MainnetSettler in the alert and PoC; Etherscan labels it "0x: Settler V1.6").
Settler is a swap-settlement contract that anyone can call, and it executes whatever list of actions the caller supplies. Victim 0xa31d...097b had approved HOLD to this contract, so any caller could make Settler call transferFrom on the HOLD token and move the victim's balance. The attacker did exactly that, taking 308,453,642 HOLD in transaction 0xfab5912f...8e9fa2. TenArmor flagged the attack and told users to revoke any approvals to the contract.
How it happened
- The victim wallet
0xa31d...097bhad an outstanding ERC-20 approval for HOLD tokens granted to the Settler contract0x70bf...4710. - The attacker (
0x3a38...f2d9) deployed an attack contract whose constructor called Settler's publicexecutefunction, with an empty slippage check and a single crafted action. - That action pointed Settler at the HOLD token and carried
transferFrom(victim, attacker, 308453642481581939556432141)calldata, so Settler made the call as the approved spender. - Because the victim had approved Settler, the HOLD token honoured the transfer, and about 308.45M HOLD (about $66K) went straight to the attacker's address in one transaction.
Protocol details
Evidence
- report TenArmor Security Alert on MainnetSettler (X post, via fxtwitter mirror) x.com
- transaction Etherscan: attack transaction 0xfab5912f...8e9fa2 etherscan.io
- address Etherscan: 0x: Settler V1.6 (0x70bf6634...4710) etherscan.io
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs MainnetSettler_exp.sol PoC raw.githubusercontent.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.