Uniswap Hack
What happened
A Uniswap liquidity provider was subjected to a phishing attack, which incurred losses of $8M. Uniswaps smart contracts were not involved in any shape or form in this phishing attack.
The victim received a fake airdrop of a lp token from the attacker disguised as a transaction coming directly from Uniswap. The attacker manipulated the trade log in order to make "Uniswap" appear as the sender of the transaction on blockscan.
The attacker set up a fake airdrop claim website upfront. When the victim tried to claim the airdrop on the phishing website, approvals were given to the attacker that enabled the hacker to gain control over the funds of the victims wallet.
The hacker exited a WBTC/USDC liquidity pool position the victim had established on Uniswap and exchanged assets for $ETH, which were withdrawn through Tornado.cash.
Uniswap was not the target of this attack, nor were any of Uniswaps smart contracts affected in this exploit.
The fake airdrop token address: https://etherscan.io/address/0xcf39b779…2ed00c
Creator of the malicious fake airdrop tokens address: https://etherscan.io/address/0x24a4b33b…2c6fd6
Hacker wallet address: https://etherscan.io/address/0x09b5027e…447afa
Callling multicall for swapping $WBTC and $USDC to $ETH transaction: https://etherscan.io/tx/0x49efa8a1…02ce2d
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report en.cryptonomist.ch
- report Report theblock.co
- report Report cointelegraph.com
- report Report decrypt.co
- report Report beincrypto.com
- analysis Web Archive web.archive.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.