T
iTokenly

Aftermath Finance (Perps) hack — April 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 29, 2026
Target typeDecentralised exchange
Loss$1,139,927Price at time of incident
MethodContract logic errorMissing lower-bound validation on the integrator ("builder code") taker fee in the perpetual futures clearing house. The contract enforced only integrator_taker_fee <= max_taker_fee and never checked that the fee was non-negative, so an attacker who set max_taker_fee to zero could supply a negative signed fixed-point value and pass validation. Subtracting a negative fee added to the trader's collateral instead of deducting from it, and the inflated synthetic collateral was withdrawn as real USDC.
ChainsSui
OutcomeUsers reimbursed

What happened

On 29 April 2026 an attacker drained roughly 1.14 million USDC from Aftermath Finance's perpetual futures market on the Sui network. Aftermath's perps contracts let third-party integrators ("builder codes") set a taker fee that is deducted from a trader's collateral at execution. The check enforced only that the integrator taker fee was less than or equal to the account's maximum taker fee, with no non-negative guard, so an attacker who set the maximum to zero could pass a negative signed fixed-point value and satisfy the test. Subtracting a negative fee increased collateral rather than reducing it, and the attacker withdrew the inflated balance as real USDC. DarkNavy's transaction-level analysis found the attacker deposited 1,100 USDC in total, 100 USDC per exploit transaction into maker-side accounts, and netted 1,139,927.48 USDC across eleven profitable transactions, the first at 08:55:50 UTC and the last at 09:31:49 UTC, a window of just under 36 minutes. The exploiting address. DarkNavy traced the cash-out on Sui: about 939,000 USDC moved to fresh addresses across nineteen transfer-only transactions, and roughly 200,000 USDC was swapped into about 213,338 SUI, most of which was forwarded onward. It named no exchange destination; one contemporary report speculated that some funds may have reached KuCoin. Aftermath paused perpetuals and stated that only the perps module was affected, with swaps, staking and its other packages untouched. The flawed signed-integer accounting had been in place since 29 August 2025 and was not caught by an OtterSec audit in November 2025. On 2 May Aftermath published a list of affected accounts and opened claims, warning that some balances needed reconciling because of withdrawals taken during the under-collateralised window. Aftermath's own announcement stated that, with support from Mysten Labs and the Sui Foundation, affected users would be compensated in full. Published figures cluster tightly at about $1.14 million. No actor has been identified.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0x1a65086c85114c1a3f8dc74140115c6e18438d48d33a21fd112311561112d41e

Sources

  1. DarkNavyOn-chain · retrieved 2026-08-01
  2. The Crypto TimesSecondary · retrieved 2026-08-01
  3. CryptopolitanSecondary · retrieved 2026-08-01
  4. Live Bitcoin NewsSecondary · retrieved 2026-08-01
  5. Gate NewsAggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Aftermath Finance (Perps) hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aftermath-finance-perps
https://itokenly.com/hacks/aftermath-finance-perps

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.