ParaSwap Hack

Reported loss $300K
Ethereum
Improper Access Control

What happened

On 20 March 2024, two days after ParaSwap launched its Augustus V6 swap router, attackers found that anyone could use the new contract to pull tokens out of wallets that had approved it. The bug sat in the router's Uniswap V3 callback, which did not properly check who was calling it.

ParaSwap paused its V6 API, and ParaSwap and whitehats rescued about $3.4M of at-risk funds. According to Revoke.cash's summary of the post-mortem, about $24K was stolen before the rescue and about $1.1M in follow-up attacks. Attackers returned about $800K after negotiations, leaving roughly $300K-$324K unrecovered. ParaSwap worked with Chainalysis and TRM Labs to trace the funds. A ParaSwap DAO vote in April 2024 used treasury funds to refund affected users. Users who approved Augustus V6 were told to revoke those approvals.

How it happened

  1. Augustus V6 exposed uniswapV3SwapCallback(), the function a Uniswap V3 pool calls during a swap to collect the input tokens.
  2. The callback did not properly check that the caller was a real Uniswap V3 pool, and it took the payer (fromAddress) from caller-supplied data.
  3. The attacker called the callback directly (or through a fake pool), naming as payer a victim who had approved Augustus V6 and naming the attacker as recipient.
  4. The router used the victim's allowance to transfer the victim's tokens (in one Ethereum example, OPSEC swapped into WETH) to the attacker.
  5. Whitehats used the same flaw to front-run attackers and move at-risk balances to safety, and returned the rescued assets to users who had revoked their approvals.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity
Protocol links Website @paraswap

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.