MonoX Hack
What happened
On November 30, 2021, an attacker exploited MonoX's single-sided AMM on Ethereum and Polygon. A swap path allowed MONO to be both the input and output token, inflating its internal virtual price and allowing the attacker to exchange overpriced MONO for the pools' real assets.
The swap function did not reject identical input and output token addresses. Applying distinct buy and sell price-update paths to the same asset broke the AMM's virtual-price accounting invariant.
Case & protocol details
Attack Timeline
MonoX independently updated the virtual price for tokenIn and tokenOut. When both addresses were MONO, the final output-side update overwrote the input-side adjustment and ratcheted MONO's price upward. The attacker repeated the same-token swap, then used the artificially expensive MONO to drain WETH, WMATIC, WBTC, stablecoins, and other pooled tokens across both deployments.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-Mortem slowmist.medium.com
- report Report twitter.com
- report Post-mortem rekt.news
- report Post-mortem medium.com
- transaction Transaction polygonscan.com
- transaction Transaction etherscan.io
- analysis Website reference knownseclab.com
- analysis Twitter/X Alert tuoniaox.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis MonoX Protocol Hack Analysis sharkteam.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.