Sorra Finance Hack

Reported loss $41K
Ethereum
Reward Logic Flaw

What happened

Sorra's staking contract on Ethereum paid SOR rewards to users who locked tokens for 14, 30 or 60 days. On 4 January 2025 an attacker drained it by withdrawing the same rewards over and over. The attacker had deposited 122,868 SOR on 21 December 2024 in the 14-day tier. Once the lockup ended, it made hundreds of tiny withdrawals across several transactions, collecting 3,071,721 SOR. It swapped the SOR for ETH on Uniswap V2. QuillAudits puts the profit at about $41,000; TenArmor and SlowMist reported a loss of about $43,000.

First attack transaction: 0x6439d63cc57fb68a32ea8ffd8f02496e8abad67292be94904c0b47a4d14ce90d Attacker: 0xdc8076c21365a93aaC0850B67e4cA5fDeC5FAb9b

How it happened

  1. On 21 December 2024 the attacker deposited 122,868 SOR into the staking contract in tier 0, which has a 14-day lockup.
  2. On 4 January 2025, after the lockup ended, it called withdraw() for 1 wei of stake. getPendingRewards() returned about 6,143 SOR in rewards, and the contract paid them out.
  3. withdraw() recorded the payout in userRewardsDistributed, but getPendingRewards() never subtracted that value. The next call therefore returned the same reward again.
  4. The attacker repeated the 1 wei withdrawal hundreds of times across several transactions, collecting 3,071,721 SOR in total.
  5. It sold the SOR for ETH on Uniswap V2.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.