Renegade recovers over 90% of funds after Arbitrum exploit

Renegade's V1 Arbitrum dark pool lost $209,000 in an exploit, but over 90% of funds were returned after negotiation. The vulnerability was isolated; other deployments are secure.

Renegade's V1 Arbitrum dark pool experienced an exploit, resulting in the loss of approximately $209,000 across 27 ERC-20 tokens. The vulnerability stemmed from the proxy contract's initializer function, allowing the attacker to inject and execute malicious logic, seize control, and drain funds. In response, Renegade initiated an onchain negotiation, offering the attacker a 10% bounty for returning the remaining funds and facing no further claims. The attacker complied, returning about $190,000 and keeping less than 10% as a bounty. Returned assets included significant amounts of USDC, wrapped Bitcoin, and wrapped Ether. Renegade confirmed the vulnerability was isolated to the V1 Arbitrum deployment, which represented only 7% of trading volume. All other deployments and funds remained secure. The team suspended V1 Arbitrum transactions and advised users to revoke token approvals for the compromised contract. The attacker claimed the action was to protect user funds and warned of risks from more sophisticated exploits.

Related Tokens

Related News