T
iTokenly

Concentric hack — January 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 22, 2024
Target typeOther
Loss$1,851,503Published estimates range $1,600,000 to $1,851,503Price at time of incident
MethodSocial engineeringA targeted social engineering attack on a team member yielded the private key to a deployer/admin wallet; the specific lure has not been disclosed by the project or by any published analysis. The attacker used the key to upgrade Concentric's vault proxy contracts to a malicious implementation exposing an adminMint function, which burned LP tokens held by the staking contract and minted equivalents to the attacker for redemption against the underlying Algebra pool. A second contract used a withdrawFromAdmin path to pull tokens from wallets that still had open approvals to Concentric vaults.
ChainsArbitrum
Attributed toUnidentified actor; CertiK linked the receiving wallets to the December 2023 OKX DEX exploiter and to the UnoRe incidentSuspected
OutcomeUnresolved

What happened

Concentric (concentric.fi), an automated liquidity manager for concentrated-liquidity pools on Arbitrum, was drained on 22 January 2024 after an attacker obtained the private key to a team deployer wallet.

Concentric said the key was lost to a targeted social engineering attack on one of its team members. Neither the project nor any published analysis has disclosed the specific lure used. With the key in hand, the attacker upgraded Concentric's vault proxy contracts to a malicious implementation. The new code exposed an adminMint function that burned LP tokens held by the staking contract and minted equivalents to the attacker, who redeemed them against the underlying Algebra pool and repeated the cycle, swapping the proceeds to ether. A second contract used a withdrawFromAdmin path to pull tokens from users who still had open approvals to Concentric's vaults.

Figures differ because they cover different parts of the loss. CertiK's analysis put the total at approximately $1.85 million, split as roughly 715 ETH, about $1.696 million, taken from the vaults and 65.4 ETH, about $155,500, taken via user approvals. Neptune Mutual's own tracing recorded 715.7 ETH, about $1.72 million, from the vaults alone, and early coverage citing CertiK gave figures of $1.6 million and $1.7 million before the fuller analysis was published.

CertiK also stated that the wallets receiving the funds were linked to the December 2023 OKX DEX exploit and to an incident affecting UnoRe. No individual or group has been formally identified or charged. Concentric halted the protocol and told users to revoke approvals to its vault addresses. No recovery of the stolen funds has been reported.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. Neptune MutualSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01
  4. GenfinitySecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Concentric hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/concentric-finance
https://itokenly.com/hacks/concentric-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.