SIR Hack

TOTAL LOST $355K
Low Access Control Attacks ethereum

What happened

On March 30, 2025, SIR (Synthetics Implemented Right) was exploited for $355,000 due to improper use of transient storage (EIP-1153) in the uniswapV3SwapCallback() function, allowing an attacker to manipulate storage and mint synthetic assets without authorization.

The Vault contract used transient storage to store the Uniswap V3 pool address at slot 0x1, but later overwrote it with a user-controlled amount within the same transaction. This allowed the attacker to bypass authentication checks and execute unauthorized minting of synthetic assets. The vulnerability was due to not clearing transient storage after authentication, enabling the attacker to repeatedly call the function with manipulated data.

The stolen WETH was laundered via ParaSwap, Odos Router V2, and Railgun, making tracking difficult. The SIR team acknowledged the breach and is investigating recovery options.

Case & protocol details

Classification Protocol Logic / Exchange (DEX) / Access Control
Protocol Type Derivatives
Smart Contract Language Solidity
Official Website app.sir.trading/
Protocol Twitter/X @leveragesir

Market Context at Time of Hack

Token Price at Hack $0.0156
Token Categories
AI & Big Data Memes BNB Chain Ecosystem AI Agents Binance Alpha Four.Meme Ecosystem Binance Ecosystem Binance Listing

Security review history

Evidence & learning

Proof of concept

1 available

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.