Rigoblock Hack
What happened
On February 17, 2022, RigoBlock's Drago token pools on Ethereum were exploited through a missing access control. The Drago function setMultipleAllowances() was supposed to be owner-only but lacked the onlyOwner modifier, so anyone could call it to set token allowances on a pool, which put every token held in Dragos except ETH and USDT at risk. The flaw was later recorded as CVE-2022-25335. About 160.86 ETH, roughly $464,000, was taken.
RigoBlock confirmed the hack the same day and told users to stop using the protocol, saying a proper fix would need a major protocol upgrade, while pool purchases and withdrawals remained safe. A whitehat who front-ran part of the attack returned the recovered funds to the affected pool on February 20, keeping a 10% bug bounty. RigoBlock said it contacted Ethermine about the remaining funds from the whitehat's front-run transaction and planned to use treasury funds to compensate affected pools. Example exploit transaction: 0x5a6c108d5a729be2011cd47590583a04444d4e7c85cd0427071b968edc3bfc1f.
Protocol details
Evidence
- report RigoBlock on X: 'RigoBlock has been hacked...' (Feb 17, 2022, via fxtwitter API) twitter.com
- report RigoBlock on X: whitehat returned funds minus 10% bounty (Feb 20, 2022, via fxtwitter API) twitter.com
- report danielvf on X: 'Drago just got Rekt' (Feb 17, 2022, via fxtwitter API) twitter.com
- code GHSA-7c5g-cjm9-2jm4 / CVE-2022-25335: RigoBlock Dragos lacks onlyOwner for setMultipleAllowances github.com
- analysis DeFiLlama defillama.com
- analysis Feb 2022 - RigoBlock Missing Access Controls - $464k (Quadriga Initiative) quadrigainitiative.com
- analysis rigoblock.com page rigoblock.com rigoblock.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.