MonoSwap Hack

Reported loss $1.3M
Blast
Access Control

What happened

On July 24, 2024, MonoSwap, a DEX and staking platform on Blast, announced that it had been hacked and that the attacker had withdrawn most of the staked liquidity on the platform. The breach started with social engineering, not a smart contract bug. Scammers posing as venture capitalists invited a MonoSwap developer to a call and told him to install a video-call app presented as Kakao. The app was malware. It gave the attackers access to the developer's office PC, which held keys to all MonoSwap-related wallets and contracts.

With those keys the attacker pulled the staked liquidity out of MonoSwap's pools. Reported losses are about $1.3 million, which Web3 Is Going Great, citing PeckShield, says was laundered through Tornado Cash. MonoSwap told users to withdraw their positions immediately, not to add liquidity or stake, and not to open the malicious link. The team said it was planning refund options and would try to recover the funds.

The root cause was operational: one developer machine held privileged keys with wide control over the protocol's wallets and contracts, so a single malware infection was enough to drain user liquidity.

How it happened

  1. Scammers posing as venture capitalists contacted the MonoSwap team about a possible investment and set up a call.
  2. To join, a MonoSwap developer installed a video-conferencing app presented as Kakao on his office PC. The app was infostealer malware.
  3. The malware gave the attackers access to the private keys on that machine, which controlled all MonoSwap-related wallets and contracts.
  4. Using that access, the attacker withdrew most of the staked liquidity from MonoSwap, roughly $1.3 million, and then laundered it through Tornado Cash.

Protocol details

Classification Exchange (DEX) / Infrastructure / Social Engineering
Protocol Type Exploit/Access control
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.