Revoke.cash logo

Unizen Hack

Check if your address is affected.

8 Mar 2024
$3.2M stolen
Ethereum Logo

Unizen is a cross-chain DEX aggregator, a service that looks for the best trading prices across many exchanges. Its users approved its aggregation contract on Ethereum to spend their tokens when trading. On 8 March 2024, Unizen upgraded this contract to a new version that was meant to reduce gas fees. The new version passed on instructions to other contracts without checking where they were going, so anyone could use it to move tokens out of wallets that had approved it. Attackers quickly started abusing the flaw.

About $3.6M was drained before Unizen rolled the contract back to its previous version around eleven hours later. Some of the attackers returned roughly $310k, so attackers kept around $3.2M. Unizen offered a 20% bounty for the return of the remaining funds and started reimbursing affected users in USDT and USDC on 11 March 2024. The reimbursements were paid mainly from an interest-free personal loan by Unizen's CEO, Sean Noga, rather than out of recovered funds.

The flaw was closed when Unizen rolled back the upgrade, and the contract has been upgraded several times since. It stayed in normal use for around two years after the incident, so approvals to it no longer carry a risk from this exploit. As with any contract you no longer use, it is still good practice to revoke approvals you do not need anymore.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:x.com•x.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits