Revert Finance Hack

TOTAL LOST $30K
Low Access Control Attacks ethereum

What happened

Revert Finance was exploited via the allowances issue. Roughly 30,000 $USD worth of funds were stolen from the user's wallets.

Revert Finance is a Yield Aggregator which provides tools for various AMMs in four chains - Ethereum, Polygon, Arbitrum, and Optimism. The project's V3Utils contract that was deployed on 3 February 2023 was exploited, allowing the attacker to drain user funds. The total stolen amount is nearly 30,000 $USD, where the majority is 22,983 $USDC.

All the lost funds were compensated to the affected users as airdrops.

Attacker address:

https://etherscan.io/address/0x38f887a0…f32f70

Malicious contract:

https://etherscan.io/address/0xd346f652…61fb27

Malicious transaction:

https://etherscan.io/tx/0xdaccbc43…3f31d5

Case & protocol details

Classification Yield Aggregator / Access Control
Protocol Type Exit Scam/Abandoned
Smart Contract Language Solidity
Official Website revert.finance/
Protocol Twitter/X @revertfinance

Security review history

Bug bounty Immunefi Details

Funds Recovery

100.0%

Recovered

$30K

Net Loss

$0

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.