VeloraDEX Hack
What happened
On October 7, 2025, an attacker exploited a known Augustus V6 callback vulnerability affecting VeloraDEX, formerly ParaSwap. A wallet that had not revoked its token approval was drained of approximately $20,000 in USDC on Ethereum.
Case & protocol details
Attack Timeline
Augustus V6 did not sufficiently verify the caller of UniswapV3SwapCallback() in some execution paths. An attacker could impersonate a pool through a malicious contract and trigger the callback against a user who had previously approved Augustus V6, transferring approved tokens without a legitimate swap. VeloraDEX had disclosed and mitigated the vulnerability in March 2024, but approvals left in place still exposed affected wallets.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.