SharedStake Hack

REPORTED LOSS $500K
Low Access Control ethereum

What happened

Some members of the SharedStake core team claimed that a SharedStake insider, who was given access to the bug report of critical timelock vulnerability by the SharedStake team, appears to have used the vulnerability to exploit the SharedStake contracts four times for approximately $500,000 on June 19 and June 23.

SharedStake rogue insider tests exploit on mainnet:

https://etherscan.io/tx/0x9400daa8…332c9f

SharedStake rogue insider exploits more timelocks on mainnet:

https://etherscan.io/tx/0x68dcf70e…6f38c5

https://etherscan.io/tx/0x466bca01…79cf39

https://etherscan.io/tx/0x2dff7aa6…328313

Some of the resulting funds have been swapped to a mix of USDC and vETH2.

Case & protocol details

Classification Yield Aggregator / Access Control
Protocol Type Liquid Staking
Affected asset / contract SGT
Implementation language Solidity
Official Website www.sharedstake.org/
Protocol Twitter/X @SharedStakeOrg

Security review history

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.