Swerve Finance Hack

TOTAL LOST
Other

What happened

Swerve Finance's pool was targeted via governance attack which might cause a loss of 1,337,000 $USD

Swerve Finance, a defunct clone of Curve Finance, was targeted in a governance exploit attempt. The attacker created a proposal to transfer 1,337,000 $USD from the DAI-USDC-USDT pool to their address. Initially, the attacker had 348,000 $SWRV tokens and later gained another 102,000 $SWRV tokens to control enough power for their proposal to pass. However, it is still ongoing as they lack sufficient combined power.

The party behind the attack claims that it was a white hat effort to claim admin fees worth 120,000 $USD and that exploiting the protocol's vulnerability was accidental.

This incident highlights how decentralized governance mechanisms can protect large sums but also demonstrates potential vulnerabilities when projects are abandoned or handed over without proper consideration for security measures such as transferring ownership of the project's null address which could provide better protection against malicious takeover attacks.

Attacker address:

https://etherscan.io/address/0xcdedb901…186ca7

Malicious transaction:

https://etherscan.io/tx/0x4c612aea…75a2fa

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Affected asset / contract SWRV
Official Website swerve.fi/
Protocol Twitter/X @SwerveFinance

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.