SushiSwap Hack
What happened
In April 2023, SushiSwap's RouteProcessor2 router accepted an attacker-controlled route that named a malicious pool as a Uniswap V3 pool. The router then treated the malicious pool as the authorized callback caller, allowing it to invoke uniswapV3SwapCallback and transfer WETH from wallets that had approved RouteProcessor2. The main documented theft was about 1,800 WETH from an Ethereum wallet.
Case & protocol details
Attack Timeline
RouteProcessor2 parsed a pool address from attacker-controlled route data without verifying that it was a genuine Uniswap V3 pool. The attacker supplied a malicious pool whose swap call invoked the router's callback. Because the router had recorded the attacker-controlled address as the last pool, its callback check passed and transferred WETH from an approved wallet.
The vulnerable router had deployments on 14 networks, creating multi-chain approval exposure, but the principal documented theft was on Ethereum. Sushi removed the router, coordinated rescues, and opened claims for affected users.
Security review history
- PeckShield Report
Funds Recovery
Recovered
$723K
Net Loss
$2,783,724
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report x.com
- report Sushi: RouteProcessor2 post-mortem sushi.com
- transaction Transaction etherscan.io
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference cointelegraph.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis SharkTeam: SushiSwap attack analysis sharkteam.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.