Renegade Hack
What happened
On 10 May 2026, Renegade's legacy V1 Dark Pool proxy on Arbitrum was exploited for about $209,000. A deployment and migration failure left an initialization path callable, allowing an attacker to inject malicious delegatecall logic and sweep dozens of ERC-20 balances. Renegade reported that about $190,000 was returned through an on-chain recovery agreement.
The proxy did not safely close and authorize its initialization/control path. A migration-state mismatch enabled an arbitrary caller to re-initialize addresses later used as a delegatecall target, executing attacker code in the asset-holding proxy context.
How it happened
- The affected deployment was the legacy V1 Arbitrum proxy, not Renegade's V1 Base or V2 deployments.
- Renegade attributed the incident to a deployment path without an explicit owner combined with a faulty migration that left version state out of sync.
- An attacker could call the remaining initializer with attacker-controlled logic or configuration addresses.
- The proxy then reached that logic through delegatecall, executing attacker code in the proxy's storage and balance context and transferring its held ERC-20 assets.
- The on-chain transaction shows 26 token transfers from the Dark Pool proxy to the attacker; public reports differ slightly on the total asset count, so the page avoids making the count central.
Protocol details
Security review history
- OpenZeppelin View report
Funds Recovery
Recovered
$190K
Net Loss
$19,019
Evidence
Proof of concept
1 availableSources
- report Renegade incident statement x.com
- report Twitter/X Alert x.com
- report Blockaid incident alert x.com
- report @renegade_fi incident report x.com
- transaction Renegade exploit transaction arbiscan.io
- code DeFiHackLabs Renegade analysis github.com
- analysis DeFiLlama defillama.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.