Visor Finance Hack

REPORTED LOSS $505K
Low Access Control ethereum

What happened

Visor Finance's June 2021 incident involved a compromised administrator account. The attacker used an emergency-withdraw capability to take approximately $500,000 in deposits that had not yet entered liquidity-provider positions. Visor said treasury funds reimbursed the affected users.

Technical Root Cause

A single account could exercise privileged Hypervisor withdrawal functions. Compromising that account exposed unallocated deposits; Visor stated that the incident did not exploit its smart-contract code.

Case & protocol details

Classification Yield Aggregator / Access Control
Protocol Type Exploit/Access control
Affected asset / contract VISR
Implementation language Solidity
Official Website www.visor.finance/
Protocol Twitter/X @visorfinance

How it happened

  1. The attacker obtained access to an account controlling Hypervisor administrative functions.
  2. They used the emergency-withdraw capability to remove unallocated deposits.
  3. Visor replaced the stolen amounts from its treasury and said it had corrected the use of single-account administrative control.

Funds Recovery

100.0%

Recovered

$505K

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.