Scroll Token Hack

Reported loss Not disclosed
Ethereum
Arithmetic Error

What happened

On May 28, 2024 (23:21 UTC), an attacker drained 76.36 WETH, roughly $295,000 at the time, from the Uniswap V2 pool of an ERC-20 token called Scroll Network (SCROLL). The contract is unverified. Verichains, working from decompiled code, says it appears to have been compiled with Solidity 0.8.19 and that its transfer code seems to subtract the amount from the sender's balance inside an unchecked block, which switches off Solidity 0.8's built-in underflow check.

By making a zero-balance address send 1 wei of SCROLL, the attacker underflowed that address's balance to a near-maximum value. They then dumped about 136 million SCROLL into the pool and withdrew all of its WETH. The token's price fell by about 99.99%. The attack transaction is 0x661505c39efe1174da44e0548158db95e8e71ce867d5b7190b9eabc9f314fe91, sent by 0x55Db954F0121E09ec838a20c216eABf35Ca32cDD through attack contract 0x55f5aac4466eb9b7bbeee8c05b365e5b18b5afcc. Cointime reported that the attacker was funded through Tornado Cash.

How it happened

  1. The attack contract called Uniswap's Universal Router execute with a TRANSFER command, so the router, which held no SCROLL, called SCROLL transfer to send 1 wei to the token creator's address.
  2. Instead of reverting, the router's balance of 0 underflowed to a huge number. Verichains attributes this to the sender-side subtraction sitting in an unchecked block in the decompiled code.
  3. The attacker issued another TRANSFER command, moving roughly 136 million SCROLL (1,000 times the pool's SCROLL reserve) from the router to the SCROLL/WETH Uniswap V2 pair.
  4. They called swap on the pair and took 76.36 WETH, emptying the pool's WETH, then unwrapped it to ETH.
  5. In the DeFiHackLabs reproduction, a final TRANSFER sends the router's remaining inflated SCROLL balance to the attacker.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.