Dexible Hack
Check if your address is affected.
Dexible was a DEX aggregator, a service that searches several exchanges to find the best price for a token swap, available on several chains. To use it, traders approved Dexible's contracts to spend their tokens. On 17 February 2023, an attacker exploited a flaw in the newest version of these contracts. When making a swap, users could tell Dexible which exchange to route the trade through, but the contract never checked that this was a real exchange. The attacker pointed it at token contracts instead and told them to hand over the tokens users had approved.
The attacker took over $2M, roughly $1.5M on Ethereum and $450k on Arbitrum, and sent the stolen funds through the Tornado Cash mixer to hide their trail. Dexible paused its contracts and urged users to revoke their approvals on every chain where it was deployed, even though no funds were drained outside Ethereum and Arbitrum. The team was criticized for its slow public response, as its announcement came more than nine hours after the attack. The newest contracts had also not been through an external audit.
Pausing a contract is not the same as fixing it, and a paused contract can be switched back on. The vulnerable Dexible contracts exist on Ethereum, Arbitrum, BNB Chain, Polygon, Optimism and Avalanche. If you ever used Dexible on any of these chains, check your wallet and revoke your approvals to it. Revoking protects the tokens that are still in your wallet, but it does not recover funds that were already stolen.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →