CivTrade Hack
Check if your address is affected.
CivTrade was a trading app from CivFund that let people place limit orders on Uniswap V3, meaning trades that only happen once a token reaches a chosen price. To use it, people approved CivTrade's contracts to spend their tokens, often without any limit. On 8 July 2023, attackers found that a part of the contract meant to be used only by Uniswap could be called by anyone. By setting up a fake Uniswap pool, they tricked the contract into moving tokens out of wallets that had approved it.
The first wave hit the newer version of CivTrade early that morning, and a second wave drained the older version later the same day. Together the attacks on Ethereum took over $270k in tokens, including stablecoins such as DAI, and much of the loot was swapped to ETH and sent to the Tornado Cash mixer. CivFund paused the newer contract within hours, told users to revoke their approvals and then paused all CivTrade contracts. It said the flawed code had been copied from another audited project and was also missed in its own audit.
CivFund said it hoped to compensate affected users and to negotiate with the attackers, but it is not known whether any funds were returned or repaid. CivTrade was never relaunched, and its contracts were paused rather than fixed. If you ever approved CivTrade on Ethereum or Polygon, revoke those approvals. Revoking protects the tokens still in your wallet, but it does not recover funds that were already taken.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →