mySwap CL Hack
What happened
mySwap CL, the concentrated-liquidity product of the Starknet DEX, lost approximately $300K–$305K on June 19, 2026. The remaining liquidity had been closed to new deposits for more than six months but was still held across more than 100,000 residual positions.
The CL pool and shared-vault accounting trusted an attacker-controlled token and failed to enforce a safe token-admission boundary. That validation gap let the attacker manipulate join/exit accounting and over-withdraw real liquidity without privileged access.
How it happened
The attacker deployed a fake token named EVIL and introduced it into mySwap CL pools. The malicious token distorted the accounting path tied to the shared vault, allowing the attacker to withdraw real assets including ETH, USDC, USDT, and STRK; the stolen assets were later bridged and routed through Railgun.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.