Revoke.cash logo

Auctus Hack

Check if your address is affected.

26 Mar 2022
$750k stolen
Ethereum Logo

Auctus was a decentralized options protocol on Ethereum where people could create and trade crypto options. One of its older beta contracts, ACOWriter, let users create options and sell them on an exchange in a single step, which meant approving it to spend their tokens. The contract let whoever called it decide which exchange to use and what instructions to send, without checking either. On 26 March 2022, attackers abused this to make the contract pull approved tokens straight out of users' wallets.

More than $750k was taken in total, most of it in the main theft on 26 March, with smaller copycat drains following once the flaw became known. Auctus published an urgent warning on 29 March 2022, three days after the main theft. It asked everyone who had ever approved the ACOWriter contract to revoke that approval, and advised people not to move any tokens into their wallet before revoking, since those tokens could be taken as well.

That warning is still the most recent post on the Auctus blog, and the ACOWriter contract remains on-chain. This means any wallet that still has an active approval to it is at risk, even years later. If you ever used Auctus, check for approvals to ACOWriter and revoke them before adding any of the approved tokens to that wallet. Revoking protects what you hold now, but it cannot recover tokens that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:medium.com•x.com•x.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits