Voltage V3 Hack

Reported loss $322K
Fuse
Improper Access Control

What happened

On 18 March 2025, $171,027.20 in USDC.e and $151,085.87 in WETH were stolen from Voltage Finance's Simple Staking pools on Fuse Network, about $322,000 in total. According to Voltage's post-mortem, the developer who deployed the SimpleChefStaking contract kept control of it instead of handing ownership to the team. The attacker used that control to point the proxy at a malicious implementation, drained the pools through a forceWithdraw function, and immediately restored the original implementation.

The funds were bridged to Ethereum and laundered through KuCoin and swap services. Voltage revoked the developer's access and filed police reports, while saying it had not confirmed that the developer was the attacker. It said its other contracts stayed under multisig control and were not affected.

It offered the attacker a $50,000 bounty for returning all the funds, and later said it was working with law enforcement in Gibraltar and Singapore and with KuCoin, HTX and ChangeNow to recover the money.

How it happened

  1. The attacker's wallet was funded with ETH withdrawn from HTX through an intermediate address. It bought FUSE through ChangeNow and bridged it to Fuse Network via LayerZero.
  2. The SimpleChefStaking proxy had never been handed to the team's multisig after deployment. Using it, the attacker upgraded the proxy to a malicious implementation.
  3. The malicious implementation's forceWithdraw function drained about $171k in USDC.e and $151k in WETH from the Simple Staking pools.
  4. The attacker switched the proxy back to its original implementation straight away, then bridged the USDC and WETH to Ethereum.
  5. On Ethereum, the funds passed to another wallet, some went into KuCoin, and swapped proceeds were withdrawn back to the first attacker wallet.

Protocol details

Classification Access Control
Protocol Type DEX
Implementation language Solidity
Protocol links Website @voltfinance

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.