Saddle Finance Hack
What happened
On April 30, 2022, a series of Ethereum transactions exploited Saddle Finance's sUSD MetaPool and put roughly $11 million in assets at risk. A whitehat intervention saved part of the affected funds before the malicious transactions drained the remainder. The issue was an incomplete deployment fix: the live sUSD V2 MetaPool was still using an old MetaSwapUtils library with incorrect LP-token price scaling.
The deployed MetaSwapUtils swap calculation did not apply the base pool's virtual price when pricing LP-token inputs and outputs. This made the swap path inconsistent with the intended metapool accounting and created a profitable round-trip trade.
Case & protocol details
Attack Timeline
The attacker used flash liquidity to acquire USDC, moved through sUSD and Saddle LP-token swaps, and repeatedly exploited the pool's distorted accounting. In a correctly implemented metapool, a base-pool LP token is scaled by its virtual price when the swap is priced. Saddle's vulnerable swap path omitted the corresponding scale-up and scale-down operations.
A swap from sUSD to saddleUSD could therefore leave the invariant at an artificially favorable state; swapping back withdrew more sUSD than the attacker supplied. Repeating the cycle compounded the pricing error until the pool's liquidity was drained.
Funds Recovery
Recovered
$2.5M
Net Loss
$8,503,000
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-mortem medium.com
- report Post-mortem rekt.news
- code Code reference github.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference twitter.com
- analysis How to Exploit the Same Vulnerability of MetaPool in Two Different Ways (Nerve Bridge / Saddle Finance) blocksecteam.medium.com
- analysis Detecting Exploits Before Funds Are Lost Using Attack Simulation forta.org
- analysis Hack Analysis: Saddle Finance, April 2022 imtr.net
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.