SpookySwap Hack
What happened
On November 18, 2023, SpookySwap warned users not to trade on its DEX while it investigated a vulnerability in its web frontend. In its post-mortem the next day, the team said a third-party JavaScript plugin had let code be injected through npm packages. The injected code replaced the Spooky router address in the frontend with a malicious contract that sent users' swap funds to the attacker. It ran for about an hour until the team noticed and took the site down.
About $5,000 was stolen from users. SpookySwap said its contracts, LPs and farms were never at risk and promised to repay affected users from its treasury. The team kept the site offline while it updated and audited its npm dependencies, then relaunched the frontend on November 27, 2023.
How it happened
- A third-party JavaScript plugin used by the Spooky frontend allowed code injection from npm packages.
- The injected code swapped the legitimate Spooky router address in the frontend for a malicious contract.
- When users swapped through the site, their funds went to that contract, which sent them on to the attacker.
- After about an hour the team took the domain down and posted a warning (00:48 UTC, November 18) not to transact on the DEX.
Protocol details
Security review history
- CertiK View report
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.