Renegade Hack

Reported loss $209K
Arbitrum
Unprotected Initializer

What happened

On 10 May 2026, Renegade's legacy V1 Dark Pool proxy on Arbitrum was exploited for about $209,000. A deployment and migration failure left an initialization path callable, allowing an attacker to inject malicious delegatecall logic and sweep dozens of ERC-20 balances. Renegade reported that about $190,000 was returned through an on-chain recovery agreement.

Technical root cause

The proxy did not safely close and authorize its initialization/control path. A migration-state mismatch enabled an arbitrary caller to re-initialize addresses later used as a delegatecall target, executing attacker code in the asset-holding proxy context.

How it happened

  1. The affected deployment was the legacy V1 Arbitrum proxy, not Renegade's V1 Base or V2 deployments.
  2. Renegade attributed the incident to a deployment path without an explicit owner combined with a faulty migration that left version state out of sync.
  3. An attacker could call the remaining initializer with attacker-controlled logic or configuration addresses.
  4. The proxy then reached that logic through delegatecall, executing attacker code in the proxy's storage and balance context and transferring its held ERC-20 assets.
  5. The on-chain transaction shows 26 token transfers from the Dark Pool proxy to the attacker; public reports differ slightly on the total asset count, so the page avoids making the count central.

Protocol details

Classification Access Control / Proxy Initialization
Protocol Type DEX
Implementation language Solidity
Protocol links Website @renegade_fi

Security review history

Funds Recovery

90.9%

Recovered

$190K

Net Loss

$19,019

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.