Parity Multisig Hack
What happened
On November 6, 2017, a user initialized Parity's uninitialized shared multisig-wallet library, made themselves its owner, and then destroyed it. The destruction did not transfer the wallets' assets; it removed the shared code required by 587 dependent wallets and froze 513,774.16 ETH plus additional tokens.
A shared delegatecall target retained public initialization and destructive wallet functionality despite being a library. The deployed library had its own mutable state and was never initialized or protected from direct calls.
How it happened
- Each thin Parity multisig wallet delegated state-changing calls to one shared library.
- Because the library itself had never been initialized, initWallet accepted an external call and assigned ownership.
- The new owner then called kill, executing selfdestruct.
- Dependent wallets continued pointing to that address but could no longer execute their wallet logic, so their assets became inaccessible.
Protocol details
Evidence
- report Report blog.openzeppelin.com
- report @ParityTech incident report twitter.com
- report A Postmortem on the Parity Multi-Sig Library Self-Destruct medium.com
- report List of Ethereum Smart Contracts Post-Mortems forum.openzeppelin.com
- transaction Parity Multisig Library Self-Destruct Transaction etherscan.io
- analysis Website reference hackernoon.com
- analysis Blog reference blog.openzeppelin.com
- analysis DeFiLlama defillama.com
- analysis The Parity Wallet Hack Reloaded openzeppelin.com
- analysis The Parity Wallet Hack Explained openzeppelin.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.