Roll Hack

Reported loss $5.7M
Ethereum
Private Key Compromised (Unknown Method)

What happened

On 14 March 2021 an attacker obtained the private key of the hot wallet that the social money platform Roll used to hold creator tokens, and drained about $5.7 million worth of 42 different social tokens, including WHALE, FWB, KARMA, JULIEN, 1337, MORK, CHERRY, FAMILY, BEAR, SKULL, LADZ, RARE, ALEX and PICA. The attacker sold the tokens on Uniswap for ETH, which crashed their prices, and sent the ETH to Tornado Cash. More than 300 other tokens held in Roll's multisig were not affected.

Roll said the loss came from a compromise of the hot wallet's private key, not a bug in its smart contracts or in any token contract. How the key was obtained was never established: a forensic review found no anomalous logins, only a handful of employees had key access, and Roll admitted its Amazon-hosted infrastructure had never been security audited and that it had no dedicated security staff. Roll suspended social money withdrawals, moved the remaining tokens to a multisig, set up a fund for affected creators first announced at $500,000 and later raised to $750,000, and said it would move key management to AWS hardware security modules and explore MPC custody.

Attacker address: 0x5fe4e7124d1da9046edc67a6499b565241be0167 Attacker's deployed contract: 0xeaa86ddd49d8907c939413e92888536e4587bd9a Token withdrawal transactions: 0xc4b1d59c0ca5d2b0ff9d153fbcaffd3a583c792532bd13c7e93b0d1110b55d9a 0x5ebcf5b1ff3b5bf8988668b8ec89a4d3cbfcd2c10308f8b16fb44c0b7bccce3c 0xb35f41c32f278bc4decd415b3112e3f354c2668ee1248086743fa27f89d21f9e

How it happened

  1. The attacker gained control of the private key for Roll's hot wallet. The method is unknown; Roll's investigation did not identify it.
  2. From address 0x5fe4e7124d1da9046edc67a6499b565241be0167, the attacker called a pull(address from, address[] tokens) function on a contract it had deployed (0xeaa86ddd49d8907c939413e92888536e4587bd9a), moving batches of social tokens out of the hot wallet. The first transaction alone moved 14 tokens, including WHALE, FWB and KARMA.
  3. The attacker sold every token into its Uniswap liquidity pool for ETH, crashing the price of each token.
  4. The ETH was sent to Tornado Cash.
  5. Roll suspended social money withdrawals, moved the remaining tokens to a multisig and set up a creator fund of $500,000, later raised to $750,000.

Protocol details

Classification Infrastructure / Other / Key Compromise
Protocol Type Exploit/Access control
Protocol links Website @tryrollhq

Funds Recovery

13.2%

Recovered

$750K

Net Loss

$4,947,600

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.