Wintermute Hack

TOTAL LOST $27.6M
High Other

What happened

Wintermute was exploited for approximately $27.6M due to an address error.

The funds were supposed to be sent to Wintermute by the Optimism Foundation as part of an agreement to perform Wintermute functions as a market maker on the eve of the launch of the OP token. However, Wintermute provided the address of their multisig on Ethereum as the destination address for Optimism - it was an address that they did not control. The exploiter was able to recreate the multisig address on Optimism and send himself 1M tokens. Then 1M OP was sent to Vitalic's address. The exploiter returned 17M OP on Jun 10th.

Stolen funds:

- 1M OP tokens

Exploiter address: https://optimistic.etherscan.io/address/0x60b28637…ba5107

Transaction behind the attack: https://optimistic.etherscan.io/tx/0xe9491bfb…dee303

Transaction of returning funds: https://optimistic.etherscan.io/address/0x4f3a120e…31cb81#tokentxns

Case & protocol details

Classification Other
Protocol Type Exploit/Other
Official Website www.wintermute.com/
Protocol Twitter/X @wintermute_t

Funds Recovery

85.0%

Recovered

$23.5M

Net Loss

$4,140,000

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.