The R0AR Hack
What happened
On April 16, 2025, the R0AR staking contract for the $1R0R token on Ethereum was drained through a backdoor planted when the contract was deployed. Losses were about $790,000. Metaverse Post put the take at 493.7 ETH, and R0AR said the contract held about $785,000 in assets.
SlowMist found that the R0ARStaking contract wrote directly to storage during deployment to give the address 0x8149f77504007450711023cf0eC11BDd6348401F a large staked balance (user.amount) it never deposited. The attacker then used the emergencyWithdraw() function to pull the contract's funds and sold the $1R0R for ETH.
R0AR said the backdoor came from a trusted external contractor, not a core team member, and that it revoked the contractor's access. The stolen funds were routed through Tornado Cash. R0AR started weekly open-market buybacks and said about 100 million of the stolen tokens had been recaptured.
How it happened
- The
R0ARStakingcontract was deployed with code that wrote directly to storage slots, presetting a large staked balance (user.amount) for0x8149f77504007450711023cf0eC11BDd6348401F. - According to Cyvers, as reported by Metaverse Post, the attacker made a dust-sized deposit into the staking contract.
- The attacker called
emergencyWithdraw(). It trusted the preset balance, so the contract paid out $1R0R that had never been staked. - At 02:30 UTC on April 16, the exploiter address swapped 73 million $1R0R for about 416.8 ETH across Uniswap V2 and V3 pools.
- The proceeds were routed through Tornado Cash.
Protocol details
Evidence
- report @CertiKAlert incident report x.com
- report Report binance.com
- transaction Etherscan: R0AR Exploiter swap tx 0xf89715ae... etherscan.io
- analysis DeFiLlama defillama.com
- analysis Security Breach Hits R0AR Staking Contract, $790K In ETH Drained Via Malicious Exploit mpost.io
- analysis $1R0R Contract Exploited by External Developer; R0AR Responds with Buyback Program chainwire.org
- analysis Slow Fog: The fundamental reason for the R0AR's vulnerability is the existence of a backdoor in the contract bitget.com
- analysis DeFi project R0AR recently lost about $780,000 due to a backdoor in the contract panews.io
- analysis Apr 2025 - R0AR Ecosystem Insider Breach Malicious Contract Deployment - $780k quadrigainitiative.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.