Uniswap Hack

Reported loss $232K
Ethereum
ERC-777 sender-hook cross-contract reentrancy

What happened

On April 18, 2020, an attacker drained roughly 1,278 ETH from Uniswap V1's Ethereum ETH-imBTC liquidity pool by exploiting reentrancy made possible by imBTC's ERC-777 sender hook.

Technical root cause

Uniswap V1 assumed token transferFrom calls could not re-enter the exchange. Its swap flow made an external token call after sending ETH and before the input-token balance was reflected in reserve pricing. imBTC was a compliant ERC-777 token whose sender hook allowed the attacker-controlled contract to re-enter at that point. ERC-777 itself was not the vulnerability; the unsafe integration and missing reentrancy lock were.

How it happened

The attacker first bought imBTC with ETH, then began selling the imBTC back through Uniswap V1. The exchange paid ETH before its imBTC reserve had been updated. During imBTC's transferFrom call, the ERC-777 tokensToSend hook re-entered tokenToEthSwapInput and executed a second sale while the pool's ETH reserve had fallen but its imBTC reserve was still stale.

Repeating this reserve-pricing mismatch extracted excess ETH from the pool. The 1,278 ETH loss was roughly $232,239 to $300,000 at the time; the higher existing $1.4 million figure is not supported by the contemporaneous analyses reviewed.

Protocol details

Classification Cross-contract reentrancy
Protocol Type DEX
Affected asset / contract IMBTC
Implementation language Solidity
Protocol links Website @Uniswap

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.