The R0AR Hack

Reported loss $790K
Ethereum
Access Control

What happened

On April 16, 2025, the R0AR staking contract for the $1R0R token on Ethereum was drained through a backdoor planted when the contract was deployed. Losses were about $790,000. Metaverse Post put the take at 493.7 ETH, and R0AR said the contract held about $785,000 in assets.

SlowMist found that the R0ARStaking contract wrote directly to storage during deployment to give the address 0x8149f77504007450711023cf0eC11BDd6348401F a large staked balance (user.amount) it never deposited. The attacker then used the emergencyWithdraw() function to pull the contract's funds and sold the $1R0R for ETH.

R0AR said the backdoor came from a trusted external contractor, not a core team member, and that it revoked the contractor's access. The stolen funds were routed through Tornado Cash. R0AR started weekly open-market buybacks and said about 100 million of the stolen tokens had been recaptured.

How it happened

  1. The R0ARStaking contract was deployed with code that wrote directly to storage slots, presetting a large staked balance (user.amount) for 0x8149f77504007450711023cf0eC11BDd6348401F.
  2. According to Cyvers, as reported by Metaverse Post, the attacker made a dust-sized deposit into the staking contract.
  3. The attacker called emergencyWithdraw(). It trusted the preset balance, so the contract paid out $1R0R that had never been staked.
  4. At 02:30 UTC on April 16, the exploiter address swapped 73 million $1R0R for about 416.8 ETH across Uniswap V2 and V3 pools.
  5. The proceeds were routed through Tornado Cash.

Protocol details

Classification Other / Access Control
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol links Website @th3r0ar

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.