Swerve Finance Hack
What happened
Swerve Finance's pool was targeted via governance attack which might cause a loss of 1,337,000 $USD
Swerve Finance, a defunct clone of Curve Finance, was targeted in a governance exploit attempt. The attacker created a proposal to transfer 1,337,000 $USD from the DAI-USDC-USDT pool to their address. Initially, the attacker had 348,000 $SWRV tokens and later gained another 102,000 $SWRV tokens to control enough power for their proposal to pass. However, it is still ongoing as they lack sufficient combined power.
The party behind the attack claims that it was a white hat effort to claim admin fees worth 120,000 $USD and that exploiting the protocol's vulnerability was accidental.
This incident highlights how decentralized governance mechanisms can protect large sums but also demonstrates potential vulnerabilities when projects are abandoned or handed over without proper consideration for security measures such as transferring ownership of the project's null address which could provide better protection against malicious takeover attacks.
Attacker address:
https://etherscan.io/address/0xcdedb901…186ca7
Malicious transaction:
https://etherscan.io/tx/0x4c612aea…75a2fa
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.