Revoke.cash logo

Dolomite Hack

Check if your address is affected.

20 Mar 2024
$180k stolen
Ethereum Logo

Dolomite is a decentralized exchange and money market protocol. It first launched on Ethereum in 2019, then moved to Arbitrum in 2022 and phased out support for its original Ethereum contracts. Many early users never removed the approvals they had given to those old contracts. On 20 March 2024, an attacker found a flaw in one of these discontinued contracts that let them move tokens out of any wallet that still had an approval to it. Dolomite's current product on Arbitrum was completely separate and was not affected.

The attacker took over $1.8M from wallets on Ethereum, mostly in USDC and DAI. Dolomite suspended the vulnerable contract within an hour and told users to revoke their approvals to it. The team then contacted the attacker through on-chain messages and reached a deal, and by 24 March 2024 it had recovered 90% of the stolen funds. That left about $180k unrecovered. Dolomite chose to cover this remaining 10% from its treasury, so all affected users were made whole.

Although the contract was suspended rather than repaired, the approvals that users gave it years ago still exist until they are revoked. If you ever used the original Dolomite exchange on Ethereum, check for approvals to its old contracts and revoke them. Dolomite's newer deployments are unrelated to this issue, so they are not affected by this incident. This case shows why it is worth revoking approvals to apps you no longer use, even when the app itself has moved on.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:x.com•x.com•medium.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits