Swapos Hack
What happened
Swapos DEX was exploited on the same day it launched, with 464,026 $USD worth of assets stolen. The exploit was possible due to a vulnerable 'swap' function that allowed anyone to perform malicious swaps and
fully drain the pool.
Swapos is a DEX running on the Ethereum chain. The project offered decentralized trading with low fees. On the day Swapos V2 Contracts were deployed, a vulnerability was discovered in their 'swap' function which allowed an attacker to execute malicious swaps and fully drain all three pools, including SWP/WETH, USDC/WETH, USDC/WBTC.
In total, 464,026 $USD worth of assets were stolen from these pools. Interestingly, the exploiter executed a transaction after a hack with a message reading "safe", suggesting they may be a whitehat hacker attempting to bring attention to this vulnerability rather than committing outright theft. Regardless of intent, funds are currently held within the attacker's contract.
Attacker address:
https://etherscan.io/address/0x53fc4a4a…323ebd
Malicious transactions:
https://etherscan.io/tx/0x78edc292…82d50a
https://etherscan.io/tx/0x4c55ba0b…9f1966
https://etherscan.io/tx/0xbe643ccd…b44575
Attacker message:
https://etherscan.io/tx/0x4c37d83f…43f624
Malicious contract:
https://etherscan.io/address/0x2df07c05…bd1405
Case & protocol details
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.