T
iTokenly

Dexible V2 hack — February 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 17, 2023
Target typeDecentralised exchange
Loss$2,047,635Price at time of incident
MethodAccess control flawThe selfSwap function let callers supply their own router address and calldata without checking it against an approved list, so the attacker made the Dexible contract call token contracts directly and execute transferFrom against allowances users had granted to Dexible.
ChainsEthereum, Arbitrum
OutcomeUnresolved

What happened

Dexible was a multichain DEX aggregator. On 17 February 2023 an attacker exploited its version 2 contracts and took $2,047,635.17 from traders who had granted those contracts token spending allowances.

The vulnerability was in the selfSwap function, which let a caller supply their own routing information so a trade could be sent to a venue of their choice. The router address was never checked against an approved list. The attacker passed a token contract address and hand-crafted calldata instead of a real router, so the Dexible contract executed transferFrom against allowances users had granted to Dexible and moved their tokens to an attacker-controlled address. Because the calls originated from the contract users had already approved, the token contracts permitted them.

Dexible's post-mortem recorded 17 affected trader addresses, four on Ethereum mainnet and 13 on Arbitrum; CoinDesk's account of the affected wallets gave a slightly different split of five and 13. The team said it discovered the problem when about $50,000 belonging to a founder moved unexpectedly, paused the contracts and told users to revoke their token approvals. Chief executive Michael Coon said the contracts had been paused while the team established a full picture of the situation.

The largest single loss fell on BlockTower Capital, which Arkham Intelligence and Nansen identified from wallet analysis as having lost about $1.5 million of TRU tokens. The attacker swapped TRU for ETH on SushiSwap and routed proceeds through Tornado Cash. Roughly 85 percent of the total came from a handful of large holders. No funds were recovered and no attribution has been established.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. Cointelegraph (syndicated on TradingView)Secondary · retrieved 2026-08-01
  3. SolidityScanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Dexible V2 hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dexible
https://itokenly.com/hacks/dexible

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.