SushiSwap Hack
Incident Overview
The exploiter:
https://etherscan.io/address/0x3ddd8b6d…c45395
Sushiswap's launchpad MISO was attacked from the front end side. The anonymous contractor of the Sushiswap GitHub uploaded malicious code, which replaced the auction's wallet with the exploiter's wallet. Commit author was under the AristoK3 nickname. The exploiter's wallet was funded from exchanges like Binance, FTX.
The transaction where the funds were withdrawn:
https://etherscan.io/tx/0x78d63557…1cda44
The funds were returned back to the SushiSwap Operation Multisig wallet at:
https://etherscan.io/tx/0x4bfd68aa…748521
https://etherscan.io/tx/0x904e5bcb…08cbdb
https://etherscan.io/tx/0x421e06f9…f6fa61
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to SushiSwap, these are the critical security checks that could have prevented this incident (September 2021).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$3.0M
Net Loss
0
Security Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next SushiSwap
The SushiSwap hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.