Seneca Hack

Reported loss $6.5M
Ethereum Arbitrum
Arbitrary external call through Chamber to invoke transferFrom on approved user balances

What happened

Seneca's Chamber contracts were exploited on Ethereum and Arbitrum after an arbitrary external-call path could invoke transferFrom using user token approvals. Approximately $6.5 million was drained from approved user wallets rather than directly from deposited protocol TVL; about $5.3 million was subsequently returned under a 20% bounty arrangement.

Technical root cause

Chamber.performOperations exposed an arbitrary callee and calldata path through OPERATION_CALL. A blacklist did not provide adequate target or calldata validation, so the Chamber's existing token allowances became usable for attacker-selected transferFrom calls.

How it happened

The attacker called performOperations with action 30, which exposed the Chamber's internal arbitrary-call path. By supplying a target token and transferFrom calldata, the Chamber executed transfers from user wallets because it already had their ERC-20 approvals.

The attacker redirected approved balances to its own address. Seneca negotiated an 80% return, reported as roughly 1,537 ETH, while the remaining share was retained as the accepted bounty.

Protocol details

Classification Access control / token approval abuse
Protocol Type CDP
Affected asset / contract SEN
Implementation language Solidity
Protocol links Website @SenecaUSD

Security review history

Funds Recovery

81.5%

Recovered

$5.3M

Net Loss

$1,202,500

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.