Wise Lending V1 Hack
Incident Overview
Wise Lending protocol was exploited on Ethereum Mainnet, losing 178.19 ETH.
Wise Lending is a decentralized lending and borrowing protocol. On January 12, 2024, the protocol was exploited on the Ethereum Mainnet due to a smart contract vulnerability, which resulted in a loss of over 178.19 ETH worth approximately $449,413 USD. The root cause of the exploit is due to the precision loss in smart contract operations.
The exploiter took advantage of a nearly empty PLP-stETH-Dec2025 market in the protocol, which was deployed just a day prior to the attack incident, in order to inflate the share price. The attacker was funded by Tornado Cash and the stolen funds were transferred to another EOA.
Attacker Address:
https://etherscan.io/address/0xB90CF1d7…2B45Dc
Funds Holder as of Jan 16, 2024:
https://etherscan.io/address/0x592856d6…C52530
Malicious Transaction:
https://etherscan.io/tx/0x04e16a79…d8bc31
Malicious Contract Address:
https://etherscan.io/address/0x91c49Cc7…f9d82c
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Wise Lending V1, these are the critical security checks that could have prevented this incident (January 2024).
- Verify all logic paths related to Rounding Donation Attack / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
- 01
-
02
Web Archive https://archive.is/idQch
- 03
Learn to Prevent the Next Wise Lending V1
The Wise Lending V1 hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.