SushiSwap Hack

TOTAL LOST $3.0M
Medium Other

What happened

The exploiter:

https://etherscan.io/address/0x3ddd8b6d…c45395

Sushiswap's launchpad MISO was attacked from the front end side. The anonymous contractor of the Sushiswap GitHub uploaded malicious code, which replaced the auction's wallet with the exploiter's wallet. Commit author was under the AristoK3 nickname. The exploiter's wallet was funded from exchanges like Binance, FTX.

The transaction where the funds were withdrawn:

https://etherscan.io/tx/0x78d63557…1cda44

The funds were returned back to the SushiSwap Operation Multisig wallet at:

https://etherscan.io/tx/0x4bfd68aa…748521

https://etherscan.io/tx/0x904e5bcb…08cbdb

https://etherscan.io/tx/0x421e06f9…f6fa61

Case & protocol details

Classification Exchange (DEX),Borrowing and Lending
Protocol Type DEX
Affected asset / contract SUSHI
Official Website app.sushi.com/miso
Protocol Twitter/X @SushiSwap

Security review history

Funds Recovery

100.0%

Recovered

$3.0M

Net Loss

$0

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.