Maestro Hack
Check if your address is affected.
Maestro is a popular trading bot on Telegram that lets users buy and sell tokens straight from a chat. Behind the scenes, these trades go through Maestro's router contract, which users approve to spend their tokens. Maestro released a new version of this router on 13 October 2023, but it contained a flaw that let anyone make the router carry out any action they chose. On 24 October 2023, an attacker used this to transfer tokens out of wallets that had approved the router and sell them for ETH.
The attacker took several different tokens, but no ETH, and sold them for about 280 ETH. Maestro spotted the attack and shut it down within 30 minutes, and trading was back to normal within two hours. Within about 10 hours, Maestro had refunded every affected wallet in full. For most tokens, it bought back the exact tokens that were lost. Where there was too little liquidity to do that, it paid out the ETH value plus a 20% bonus. In total, the refunds cost Maestro around 610 ETH.
Because the router is upgradeable, Maestro was able to repair the flaw in the existing contract instead of replacing it with a new one. Maestro stated that the router is fully safe again and that users do not need to revoke their approvals or stop using it. You can still revoke your approvals to the router if you no longer use Maestro or simply want to be extra careful.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →