Vow Hack
Incident Overview
On August 13, 2024, Vow, a decentralized discount voucher issuer, suffered an exploit leading to a potential collapse of its native token VOW, with losses amounting to $1.2 million.
The vulnerability occurred during the testing of a rate setter function, which altered the amount of vUSD received per VOW token from 1 to 100. The testing period lasted only 15 to 30 seconds, but within that time, a bot managed to acquire 20 million VOW tokens valued at $6.6 million. The bot then swapped these tokens on Uniswap V2 for 452 ETH, equivalent to $1.23 million.
In response, Vow increased the token's burn rate to 50% to reduce the circulating supply back to normal levels.
Exploiter:
https://etherscan.io/address/0x48de6bf9…00c0c3
Example of exploit tx:
https://etherscan.io/tx/0x4b439b82…e5ca5f
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Vow, these are the critical security checks that could have prevented this incident (August 2024).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Vow
The Vow hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.