Seneca Hack
What happened
Seneca's Chamber contracts were exploited on Ethereum and Arbitrum after an arbitrary external-call path could invoke transferFrom using user token approvals. Approximately $6.5 million was drained from approved user wallets rather than directly from deposited protocol TVL; about $5.3 million was subsequently returned under a 20% bounty arrangement.
Chamber.performOperations exposed an arbitrary callee and calldata path through OPERATION_CALL. A blacklist did not provide adequate target or calldata validation, so the Chamber's existing token allowances became usable for attacker-selected transferFrom calls.
How it happened
The attacker called performOperations with action 30, which exposed the Chamber's internal arbitrary-call path. By supplying a target token and transferFrom calldata, the Chamber executed transfers from user wallets because it already had their ERC-20 approvals.
The attacker redirected approved balances to its own address. Seneca negotiated an 80% return, reported as roughly 1,537 ETH, while the remaining share was retained as the accepted bounty.
Protocol details
Security review history
- Halborn View report
Funds Recovery
Recovered
$5.3M
Net Loss
$1,202,500
Evidence
Proof of concept
1 availableSources
- report Twitter/X Alert twitter.com
- report @spreekaway incident report twitter.com
- report @CertiKAlert incident report twitter.com
- report @PeckShieldAlert incident report twitter.com
- report @CyversAlerts incident report twitter.com
- address Seneca Chamber Contract etherscan.io
- analysis DeFiLlama defillama.com
- analysis Seneca Attack: Hack Analysis and Proof of Concept cyfrin.io
- analysis BlockSec February 2024 Security Review blocksec.com
- analysis Seneca Hacker Returns Stolen Funds cointelegraph.com
- analysis Seneca Public Recovery Statement archive.ph
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.