VeloraDEX Hack

TOTAL LOST $20K
Low Delegatecall & Call Injection Attacks ethereum

What happened

On October 7, 2025, an attacker exploited a known Augustus V6 callback vulnerability affecting VeloraDEX, formerly ParaSwap. A wallet that had not revoked its token approval was drained of approximately $20,000 in USDC on Ethereum.

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Official Website www.velora.xyz/
Protocol Twitter/X @VeloraDEX

Attack Timeline

Augustus V6 did not sufficiently verify the caller of UniswapV3SwapCallback() in some execution paths. An attacker could impersonate a pool through a malicious contract and trigger the callback against a user who had previously approved Augustus V6, transferring approved tokens without a legitimate swap. VeloraDEX had disclosed and mitigated the vulnerability in March 2024, but approvals left in place still exposed affected wallets.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.