Tomatos Hack
What happened
The withdrawal of the user's funds was possible by the smart contract's unlimited malicious approval, which granted attacker to take DAI, TrueUSD, USDC-Tomatoes LP, USDC, USDT, and UNI from users' wallets. Users that deposited ETH during the pre-sale did not get project tokens. The project's social media is inaccessible.
Stolen funds were deposited into Tornado mixer:
- 0x96f3bae8…d53924
- 0xe908da08…c9dcee
- 0x56ddf87a…c8a880
- 0x3aa6c5c4…5692b4
- 0xcc8c4d38…d74156
- 0x1091bd2e…93f15a
- 0x7ec1bcac…fd3f7a
- 0xb0b725ca…6ac3ae
Example transactions of withdrawal from the fake contracts:
https://etherscan.io/tx/0x264e1a5a…8a11c6
https://etherscan.io/tx/0xb0b725ca…6ac3ae
https://etherscan.io/tx/0xcab4d6e0…99ddc3
https://etherscan.io/tx/0xcbf6858d…7d1d89
https://etherscan.io/tx/0x5399f79a…5b3b34
https://etherscan.io/tx/0x7d61c0b1…76ec74
https://etherscan.io/tx/0x7efa4390…9bf101
https://etherscan.io/tx/0x3e51d5f0…4addfc
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report t.me
- analysis Web Archive web.archive.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.