MixedSwapRouter Hack

Reported loss $16K
Arbitrum
Arbitrary External Call

What happened

On May 31, 2024 an attacker drained about 293,000 WINR tokens from wallets that had approved the MixedSwapRouter of WINR Protocol (the on-chain casino protocol behind JustBet) on Arbitrum. ChainAegis valued the loss at about $11,000; a Cyvers alert put the attacker's gain at about $16,000, and DeFiHackLabs lists more than $10,700.

The router's swap callback did not check that it was being called by a genuine pool, and it took the paying wallet's address from the callback data. A fake pool could therefore name any wallet that had approved the router as the payer. ChainAegis urged users to revoke approvals to the router the same day. Revoke.cash reports that the router was never changed, so any approval still given to it remains at risk.

Attacker: 0xfeef112831cc8f790abe71b4b196c220ee26ecf3 Router: 0xe3e98241cb99af7a452e94b9cf219aaa766e0869 Attack tx: 0xf57f041cb6d8a10e11edab50b84e49b59ff834c7d114d1e049cedd654c36194d

How it happened

  1. The attacker deployed a fake pool contract whose token0() and token1() both returned WINR and whose swap() function was attacker-controlled.
  2. It called swapTokensForTokens on the router, passing the fake contract in the user-supplied pool list, so the router called the fake pool's swap().
  3. Inside swap(), the fake pool called the router's algebraSwapCallback directly with callback data naming a victim wallet that had approved the router as payer.
  4. The router did not verify that the caller was a legitimate pool, so it transferred about 293,000 WINR from the victim to the fake pool, which forwarded it to the attacker.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.