Parity Multisig Hack

Reported loss $150M
Ethereum
Uninitialized library takeover followed by self-destruct

What happened

On November 6, 2017, a user initialized Parity's uninitialized shared multisig-wallet library, made themselves its owner, and then destroyed it. The destruction did not transfer the wallets' assets; it removed the shared code required by 587 dependent wallets and froze 513,774.16 ETH plus additional tokens.

Technical root cause

A shared delegatecall target retained public initialization and destructive wallet functionality despite being a library. The deployed library had its own mutable state and was never initialized or protected from direct calls.

How it happened

  1. Each thin Parity multisig wallet delegated state-changing calls to one shared library.
  2. Because the library itself had never been initialized, initWallet accepted an external call and assigned ownership.
  3. The new owner then called kill, executing selfdestruct.
  4. Dependent wallets continued pointing to that address but could no longer execute their wallet logic, so their assets became inaccessible.

Protocol details

Classification Access Control / Shared-Library Self-Destruct
Protocol Type Exploit/Other
Implementation language Solidity
Protocol links Website @ParityTech

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.