DFX Finance hack — November 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 10, 2022 |
| Target type | Decentralised exchange |
| Loss | $7,500,000Published estimates range $4,300,000 to $7,600,000Price at time of incident |
| Method | ReentrancyThe flash() function in DFX V2's Curve.sol was written without the nonReentrant modifier used elsewhere. Inside the flash-loan callback the attacker deposited the borrowed tokens back into the same pool, so the balance check treated the loan as repaid while the deposit separately minted LP tokens that were then redeemed for the pool's reserves. |
| Chains | Ethereum |
| Audited beforehand | PickAx |
| Outcome | Users reimbursed |
What happened
DFX Finance ran an automated market maker on Ethereum for stablecoin foreign-exchange pairs. Its V2 contracts, live since mid-October 2022, added a flash-loan facility. On 10 November 2022 an attacker found that the flash() function in Curve.sol had been written without the nonReentrant modifier used elsewhere in the contract. The attacker took a flash loan of pool assets and, inside the loan callback, deposited the borrowed tokens straight back into the same pool. The pool's balance check saw the funds present and treated the loan as repaid, while the deposit separately minted LP tokens to the attacker, which were then redeemed for the pool's reserves.
The reported size varies because two parties profited. Reporting by The Block and analyses by Halborn and SolidityScan put the total drained at about $7.5 million: roughly $4.3 million into the attacker's own wallet, including 2,963 ether and about $500,000 in stablecoins, and about $3.2 million captured by a front-running MEV bot that sandwiched the exploit transactions. Coinspect's technical write-up gives a lower total of more than $6 million, and early coverage counting only the attacker's wallet reported about $4 million. DFX asked the bot operator to return the extracted funds; no return has been reported.
DFX said it was notified of suspicious activity within 20 to 30 minutes of the first transaction and paused all contracts shortly after confirming the attack. The attacker moved proceeds through Tornado Cash. The vulnerable V2 code had been audited by PickAx in September 2022, which did not identify the missing modifier.
In January 2023 holders approved DIP-21, reimbursing roughly 70 affected addresses at one DFX token per dollar lost, streamed block by block over three years via Sablier.
Sources
- DFX FinancePrimary · retrieved 2026-08-01
- DFX Finance documentation (DIP-21)Primary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CoinspectSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@dfxfinance/v2-vulnerability-post-mortem-b05232bc6550
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DFX Finance hack — November 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dfx-financehttps://itokenly.com/hacks/dfx-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.