Revoke.cash logo

ParaSwap Hack

Check if your address is affected.

20 Mar 2024
$324k stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Fantom (Unsupported) Logo

ParaSwap, now called Velora, is a DEX aggregator that looks for the best prices across many exchanges. In March 2024 it launched a new version of its swap router, called Augustus V6, and users approved it so it could trade their tokens. On 20 March 2024, less than two days after the public launch, the team discovered a critical flaw that let anyone move tokens out of wallets that had approved the new router. ParaSwap immediately paused its API, removed V6 from its website and switched back to the previous version.

ParaSwap and whitehat hackers then used the flaw themselves to move about $3.4M of at-risk funds to safety, and returned them to users once they had revoked their approvals. About $24k had already been lost before this rescue. Some users later added new funds to wallets that still approved V6, and attackers took about $1.1M in follow-up attacks. After negotiations, attackers returned about $800k, leaving $324k permanently lost. In April 2024, the ParaSwap DAO voted to fund refunds from its treasury so that affected users could be paid back in full.

ParaSwap destroyed the V6 router on Polygon, BNB Chain and Avalanche, where that was possible, but the flawed contract still exists on the other chains where it was deployed. Anyone who approved Augustus V6 on any chain should revoke that approval now. The danger comes from the approval itself, so revoking removes the risk even though the contract remains. Revoking protects what is still in your wallet, but it does not recover funds that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits