Silo Hack

TOTAL LOST $545K
Low Other

Summarize with AI

Affected Chain 2025 Incident surface
Recovered - No recovery reported
All-Time Rank #980 By amount stolen
Auditors 1 Prior security audit

Incident Overview

On June 25, 2025, Silo Finance lost approximately $545,000 due to an exploit in a testing-phase smart contract for an unreleased leverage feature. Core protocol contracts, including vaults and markets, remained unaffected, with only DAO-owned funds lost.

The attacker exploited a vulnerability in the openLeveragePosition function of an experimental smart contract deployed for testing. This function allowed user-controlled inputs, which the attacker manipulated to drain funds. The attacker funded their wallet through Tornado Cash and executed the exploit before the contract was paused.

Hypernative Labs detected the malicious code 3 minutes before execution, and Silo promptly responded by isolating the module, reassuring users that no external funds were at risk.

Incident Report

Protocol / Project Silo
Date of Incident
Attack Technique Other
Classification Yield Aggregator

Protocol Information

Protocol Type Dexs
Official Website app.silo.finance/earn
Protocol Twitter/X @SiloFinance
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Price at Hack $0.0552
Market Cap at Hack $8.0M
% of Market Cap Stolen 6.84%
Token Categories
Communications & Social Media Gaming Interoperability Payments Wallet Ethereum Ecosystem Metaverse Polygon Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Silo's contract logic - root cause: yield aggregator
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Other audit checklist and test coverage
Audited by Audit Report 1 — still lost $545K. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to Silo, these are the critical security checks that could have prevented this incident (June 2025).

  • Verify all logic paths related to Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Security Audit History

Sources & References

Learn to Prevent the Next Silo

The Silo hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial