DEUS Finance (DEI stablecoin) hack — May 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 5, 2023 |
| Target type | Stablecoin or yield protocol |
| Loss | $6,500,000Published estimates range $6,000,000 to $6,500,000Price at time of incident |
| Method | Contract logic errorThe DEI stablecoin contract's publicly callable burnFrom() function read the allowance mapping with its arguments transposed, checking _allowances[msg.sender][account] instead of the ERC-20 standard _allowances[account][msg.sender]. An approval granted by user A to user B was therefore read as an approval granted by B to A. Calling burnFrom() with a burn amount of zero against a victim's address gave the caller spending rights over that victim's balance, which could then be transferred away. |
| Chains | Arbitrum, BNB Chain, Ethereum |
| Outcome | Partially recovered |
What happened
On 5 May 2023 an attacker exploited a coding error in the DEI stablecoin contract issued by DEUS Finance and took roughly $6.5 million from token holders on Arbitrum, BNB Chain and Ethereum.
The contract's burnFrom() function checked the allowance mapping with its arguments in the wrong order, reading _allowances[msg.sender][account] rather than the ERC-20 standard _allowances[account][msg.sender]. An approval that user A had granted to user B was consequently interpreted as an approval that B had granted to A. Because burnFrom() was publicly callable, anyone could invoke it with a burn amount of zero against a victim's address, acquire spending rights over that victim's DEI, and transfer the tokens away. CertiK described the same inverted mapping and noted that its earlier audit of DEUS covered the project's AMM product, not the stablecoin contract that carried the bug.
Published totals differ. Halborn broke the losses down as about $5 million on Arbitrum, $1.3 million on BNB Chain and $135,000 on Ethereum; CertiK put the total at approximately $6.5 million; Cointelegraph and crypto.news, citing PeckShield, reported "over $6 million". The range is recorded here rather than a single figure.
DEUS paused its contracts, burned DEI on-chain and published a multisig address on Arbitrum for the return of funds. Several exploit transactions were front-run by white hats. Accounts of how much was salvaged also conflict: Halborn described roughly 10 percent being returned to the project, while DailyCoin reported a recovery multisig holding 2,023 ETH worth about $3.8 million plus $158,857 in DEUS and $702,370 in USDC. DEI, already trading below peg since 2022, fell a further 30 percent.
Sources
- CointelegraphSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
- CertiKSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- DailyCoinSecondary · retrieved 2026-08-01
Official post-mortem: https://www.certik.com/blog/stablecoin-stumble-the-code-bug-led-to-usd6-5-million-loss-on-deus-finance
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DEUS Finance (DEI stablecoin) hack — May 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/deus-finance-deihttps://itokenly.com/hacks/deus-finance-deiPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.