Uniswap Hack

TOTAL LOST $8.0M
Medium Phishing Attacks

What happened

A Uniswap liquidity provider was subjected to a phishing attack, which incurred losses of $8M. Uniswaps smart contracts were not involved in any shape or form in this phishing attack.

The victim received a fake airdrop of a lp token from the attacker disguised as a transaction coming directly from Uniswap. The attacker manipulated the trade log in order to make "Uniswap" appear as the sender of the transaction on blockscan.

The attacker set up a fake airdrop claim website upfront. When the victim tried to claim the airdrop on the phishing website, approvals were given to the attacker that enabled the hacker to gain control over the funds of the victims wallet.

The hacker exited a WBTC/USDC liquidity pool position the victim had established on Uniswap and exchanged assets for $ETH, which were withdrawn through Tornado.cash.

Uniswap was not the target of this attack, nor were any of Uniswaps smart contracts affected in this exploit.

The fake airdrop token address: https://etherscan.io/address/0xcf39b779…2ed00c

Creator of the malicious fake airdrop tokens address: https://etherscan.io/address/0x24a4b33b…2c6fd6

Hacker wallet address: https://etherscan.io/address/0x09b5027e…447afa

Callling multicall for swapping $WBTC and $USDC to $ETH transaction: https://etherscan.io/tx/0x49efa8a1…02ce2d

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Phishing
Affected asset / contract UNI

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.