Shezmu Hack

TOTAL LOST $4.9M
Medium Other

What happened

On September 21, 2024, Shezmu Yield Protocol suffered a $4.9M exploit due to a vulnerability in one of its vaults, enabling the attacker to mint unlimited ShezUSD.

A flaw in Shezmu’s vault mechanism allowed an attacker to arbitrarily mint ShezUSD, effectively creating an infinite supply. This exploit occurred shortly after a smart contract upgrade, suggesting a potential oversight in the update. The attacker took advantage of the unchecked minting mechanism, draining Shezmu’s liquidity.

In response, Shezmu offered a bug bounty, successfully negotiating the return of funds.

Case & protocol details

Classification Borrowing and Lending
Protocol Type CDP
Official Website www.shezmu.io/
Protocol Twitter/X @ShezmuTech

Security review history

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.