SushiSwap Hack

TOTAL LOST $3.5M
Medium Missing Input Validation arbitrum bsc ethereum optimism

What happened

In April 2023, SushiSwap's RouteProcessor2 router accepted an attacker-controlled route that named a malicious pool as a Uniswap V3 pool. The router then treated the malicious pool as the authorized callback caller, allowing it to invoke uniswapV3SwapCallback and transfer WETH from wallets that had approved RouteProcessor2. The main documented theft was about 1,800 WETH from an Ethereum wallet.

Case & protocol details

Classification Protocol Logic / Exchange (DEX) / Input Validation
Protocol Type DEX
Affected asset / contract SUSHI
Smart Contract Language Solidity
Official Website www.sushi.com
Protocol Twitter/X @sushiswap

Attack Timeline

RouteProcessor2 parsed a pool address from attacker-controlled route data without verifying that it was a genuine Uniswap V3 pool. The attacker supplied a malicious pool whose swap call invoked the router's callback. Because the router had recorded the attacker-controlled address as the last pool, its callback check passed and transferred WETH from an approved wallet.

The vulnerable router had deployments on 14 networks, creating multi-chain approval exposure, but the principal documented theft was on Ethereum. Sushi removed the router, coordinated rescues, and opened claims for affected users.

Security review history

Funds Recovery

20.6%

Recovered

$723K

Net Loss

$2,783,724

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.