Revoke.cash logo

SushiSwap Hack

Check if your address is affected.

9 Apr 2023
$1.7M stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Gnosis Chain Logo
Arbitrum Nova Logo
Boba Logo
Fuse Logo
Fantom (Unsupported) Logo
Moonbeam (Unsupported) Logo
Moonriver (Unsupported) Logo
Polygon zkEVM (Unsupported) Logo

SushiSwap is a decentralized exchange that runs on many blockchains. Shortly before the attack, Sushi introduced a new router called RouteProcessor2 to handle swaps from its website and deployed it on 14 chains. Users who swapped approved it to spend their tokens. The router had a flaw: it did not check that requests to pay for a trade really came from a trading pool, so anyone could trick it into pulling tokens from wallets that had approved it. Security firm HYDN spotted the bug on 8 April 2023, and Sushi removed the router from its website.

A bug bounty hunter tried to rescue funds at risk, but automated bots copied the attempt and replayed the attack, taking about 1,800 WETH within seconds on 9 April 2023. Other attackers soon followed. HYDN then rescued over $750k of user funds across several chains. Of the 1,800 WETH, 885 ETH was later handed back, but about 795 ETH ended up as fees for the network's block builders and was never returned. Sushi opened a claim portal for rescued funds and promised to cover the losses that could not be recovered.

RouteProcessor2 cannot be upgraded, paused or controlled by anyone, so Sushi could not repair it and replaced it with a new router instead. The old router still exists on all 14 chains and remains vulnerable. Anyone who swapped on SushiSwap while it was live may still have an approval to it and should revoke that approval now. Revoking protects what is still in your wallet, but it does not recover tokens that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits