Revoke.cash logo

Sorbet Finance Hack

Check if your address is affected.

11 Dec 2021
$744k stolen
Ethereum Logo

Sorbet Finance was an app built by Gelato Network that let users provide liquidity to G-UNI pools on Uniswap V3. To enter a pool with just one token, users approved a router contract that swapped part of their tokens through 1inch before depositing. On 11 December 2021, researchers Yash Shah and samczsun warned Gelato that this router would carry out any instructions it was given, so anyone could use it to spend the approvals users had given it and drain their tokens.

That evening, Gelato used the flaw itself to move about $26M of at-risk funds into a secure escrow, which owners could claim back after revoking their approvals. It then ran bots to rescue tokens arriving in vulnerable wallets, saving about $1M more, and warned users through Etherscan alerts, on-chain alert messages and even an NFT airdrop. Malicious bots still beat Gelato's bots on some transactions and took about $744k. In January 2022, GEL holders voted to fund refunds for losses that happened before Gelato's cut-off of 20 December 2021.

On 17 December 2021, Gelato switched Sorbet to a new, audited contract, and its other contracts and the G-UNI pools themselves were never affected. The old router cannot be changed, so it is still vulnerable, and any approval still given to it can be used to take the approved tokens. Losses after the cut-off date are not refunded. If you ever used Sorbet Finance pools, revoke your approvals to the old G-UNI router.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits