Sorra Finance Hack
What happened
Sorra's staking contract on Ethereum paid SOR rewards to users who locked tokens for 14, 30 or 60 days. On 4 January 2025 an attacker drained it by withdrawing the same rewards over and over. The attacker had deposited 122,868 SOR on 21 December 2024 in the 14-day tier. Once the lockup ended, it made hundreds of tiny withdrawals across several transactions, collecting 3,071,721 SOR. It swapped the SOR for ETH on Uniswap V2. QuillAudits puts the profit at about $41,000; TenArmor and SlowMist reported a loss of about $43,000.
First attack transaction: 0x6439d63cc57fb68a32ea8ffd8f02496e8abad67292be94904c0b47a4d14ce90d
Attacker: 0xdc8076c21365a93aaC0850B67e4cA5fDeC5FAb9b
How it happened
- On 21 December 2024 the attacker deposited 122,868 SOR into the staking contract in tier 0, which has a 14-day lockup.
- On 4 January 2025, after the lockup ended, it called
withdraw()for 1 wei of stake.getPendingRewards()returned about 6,143 SOR in rewards, and the contract paid them out. withdraw()recorded the payout inuserRewardsDistributed, butgetPendingRewards()never subtracted that value. The next call therefore returned the same reward again.- The attacker repeated the 1 wei withdrawal hundreds of times across several transactions, collecting 3,071,721 SOR in total.
- It sold the SOR for ETH on Uniswap V2.
Protocol details
Evidence
- report TenArmor Security Alert on Sorra (X post, via fxtwitter mirror) x.com
- transaction Etherscan transaction 0x6439d63c...ce90d etherscan.io
- code DeFiHackLabs sorraStaking.sol github.com
- analysis DeFiLlama defillama.com
- analysis Sorra Finance Staking Exploit: How a $41K Hack Drained 3M SOR Tokens (QuillAudits) quillaudits.com
- analysis SlowMist Hacked: Sorra (2025-01-04) hacked.slowmist.io
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.