Merkle Trade Hack
Check if your address is affected.
Merkle Trade is a perpetual futures trading platform that runs on the Aptos blockchain. On 18 April 2024 it launched Swap & Deposit, a feature that let people on EVM chains such as Ethereum and Arbitrum swap their tokens into a stablecoin and send it to their Merkle Trade account on Aptos in one step. To use it, people approved the new contract to spend their tokens. The contract did not limit what it could be told to do, so anyone could use it to move tokens out of wallets that had approved it.
Attackers found the flaw soon after launch and took about $20k from users on Arbitrum. The contract was deployed at the same address on Ethereum, Arbitrum, Optimism, Polygon, BNB Chain and Avalanche, so approvals on all of those chains were at risk. Merkle Trade removed the feature from its app, published a guide to revoking approvals and added a pop-up asking affected users to revoke. It also flagged the attackers' addresses to major exchanges and said it would fully reimburse affected users from team funds.
The Swap & Deposit contract could not be paused or upgraded, so it remains vulnerable. Merkle Trade switched its app back to its older contract, which was not affected. If you used the Swap & Deposit feature on any EVM chain from 18 April 2024 onward, revoke your approvals to this contract on every chain where you used it. Revoking protects the tokens that are still in your wallet, but it does not recover tokens that were already taken.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →