Rigoblock Hack

Reported loss $464K
Ethereum
Improper Access Control

What happened

On February 17, 2022, RigoBlock's Drago token pools on Ethereum were exploited through a missing access control. The Drago function setMultipleAllowances() was supposed to be owner-only but lacked the onlyOwner modifier, so anyone could call it to set token allowances on a pool, which put every token held in Dragos except ETH and USDT at risk. The flaw was later recorded as CVE-2022-25335. About 160.86 ETH, roughly $464,000, was taken.

RigoBlock confirmed the hack the same day and told users to stop using the protocol, saying a proper fix would need a major protocol upgrade, while pool purchases and withdrawals remained safe. A whitehat who front-ran part of the attack returned the recovered funds to the affected pool on February 20, keeping a 10% bug bounty. RigoBlock said it contacted Ethermine about the remaining funds from the whitehat's front-run transaction and planned to use treasury funds to compensate affected pools. Example exploit transaction: 0x5a6c108d5a729be2011cd47590583a04444d4e7c85cd0427071b968edc3bfc1f.

Protocol details

Classification Access Control
Protocol Type Onchain Capital Allocator
Implementation language Solidity
Protocol links Website @rigoblock

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.