Vether Hack

Reported loss $450K
Ethereum
Improper Access Control

What happened

Vether (VETH), a "strictly scarce" ERC-20 token on Ethereum, was exploited around July 1, 2020. The attacker spent about 0.9 ETH to take 919,299 VETH held by the Vether contract itself, which SlowMist valued at about $900,000, and then sold large amounts, crashing the price. The bug came from two features working together: changeExcluded let anyone mark any address as fee-excluded for a fee, and transferFrom skipped its allowance check whenever the caller was excluded.

The Vether team said the flaw came from a UX change it had made to transferFrom and called it their fault. It said it would redeploy the token as Vether4 and compensate affected Uniswap liquidity providers.

How it happened

  1. The attacker deployed a helper contract and called changeExcluded with it, paying the 128 VETH exclusion fee. The function was external with no access control, so any address could be excluded.
  2. Once mapAddress_Excluded[msg.sender] was true, transferFrom skipped the require(value <= _allowances[from][msg.sender]) check and the allowance deduction, and went straight to _transfer(from, to, value).
  3. The helper called transferFrom with the Vether contract's own address as from, moving its 919,299 VETH to the attacker without any approval.
  4. The attacker dumped the VETH on Uniswap. The team then replaced the token with Vether4 and pledged compensation to affected liquidity providers.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.