Odin.Fun Hack

TOTAL LOST $7.0M
Medium Liquidity Manipulation Exploit / Oracle Issue / Spot Price Manipulation icp
Chain icp Primary network
Recovered - No recovery reported
Loss Rank #434 All-time
Protocol Type Exploit/Oracle Issue Target category

What happened

On August 12, 2025, Odin.fun, a Bitcoin-based memecoin launchpad and trading platform, was exploited for 58.2 BTC worth approximately $7 million. The attack involved a liquidity manipulation scheme targeting the platform's automated market-making tool, with hackers primarily linked to Chinese entities according to the co-founder's statement.

The exploit targeted a vulnerability in Odin.fun's automated liquidity market-making tool that was introduced in their latest update. The attackers executed a liquidity manipulation attack by adding tokens like SATOSHI to artificially inflate prices, then withdrawing their liquidity to receive Bitcoin returns. The platform's Bitcoin deposits dropped from 291 BTC to 232.8 BTC in under two hours as multiple threat actors took advantage of the vulnerability.

The co-founder Bob Bodily confirmed that various malicious users, primarily linked to groups in China, exploited the flaw to steal significant amounts of BTC from the platform. The company's treasury is insufficient to cover the full losses, but the team has engaged a top-tier security auditing team for a comprehensive code audit that may take up to a week. Odin.fun has contacted U.S.

law enforcement and is cooperating with major exchanges OKX and Binance, who have engaged Chinese authorities regarding the incident.

Attacker Addresses:

jeypm-z6t4p-uqshx-dtay4-qgw5d-ca7j5-alviu-fch2d-nmsnc-c4k3k-aae

urguz-m32zo-jlld6-pyy4l-z3c24-jv4pt-5fmll-gq2xd-6siiz-oxkao-xae

Case & protocol details

Classification Protocol Logic / Exchange (DEX) / Oracle Manipulation
Protocol Type Exploit/Oracle Issue
Smart Contract Language Motoko
Official Website odin.fun/
Protocol Twitter/X @Odin_GodOfRunes
Team Anonymous
Source Code Unverified

Audit assessment

Review priorities based on the documented failure pattern in Odin.Fun (August 2025).

Critical checks

  • Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
  • Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.