Unlock Protocol Hack

TOTAL LOST $38K
Low Other

What happened

On the 21th of April we has detected a security breach aimed at UnlockProtocol that resulted in a significant loss of more than 20 ETH.

The root cause of this breach is related to the "postLockUpgrade()" function in the implementation contract 0xdcb2f7d1…fd6b93, which failed to verify the caller.

During the preparation phase of the attack, the attacker called the "postLockUpgrade()" function in transaction 0x4ac413c3…033ef6. The purpose of this function call was to set the "locks[].deployed" parameter to True, allowing the attacker to pass the "onlyFromDeployedLock()" check on the "recordKeyPurchase()" function in the subsequent transaction.

It should be noted that an accomplice address, 0x3a683332…0e3c0e, was used to deposit 16 ETH into Tornado. The attacker used this address to obfuscate their tracks and make it more difficult to track the flow of funds.

Exploiter contract:

https://etherscan.io/address/0xac08f1af…152e84

Exploiter:

https://etherscan.io/address/0x43ee4169…57bb71

Case & protocol details

Classification NFT
Protocol Type Payments
Affected asset / contract UDT
Official Website unlock-protocol.com/
Protocol Twitter/X @UnlockProtocol

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.