DODO hack — March 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 9, 2021 |
| Target type | Decentralised exchange |
| Loss | $3,800,000Published estimates range $2,100,000 to $3,800,000Price at time of incident |
| Recovered | $3,100,000 |
| Method | Access control flawThe init() function on DODO V2 Crowdpooling contracts could be called again on pools that had already been initialised. Re-initialising a live pool let the attacker substitute tokens under their control while the pool still held genuine reserves, and the reserves were then moved out with the help of a flash loan. |
| Chains | Ethereum, BNB Chain |
| Outcome | Partially recovered |
What happened
On 9 March 2021 an attacker drained several DODO V2 Crowdpooling pools. DODO's own account attributes the loss to an oversight in the way the Crowdpooling contract's init() function was set up: it could be called again on pools that had already been initialised. CoinDesk described the attack as exploiting the bug to create counterfeit tokens and then moving the real assets out using a flash loan. Contemporary reporting named WSZO, WCRES, ETHA and FUSI as the affected pools. DODO ran contracts on both Ethereum and BNB Chain.
Published figures diverged while the incident was still being analysed. The Defiant reported the loss as $2.1 million and dated the attack to 8 March. CoinDesk reported $3.8 million and said DODO expected just under half of that, $1.88 million, to be returned. DODO's own subsequent accounting settled on $3.8 million taken and on 9 March as the date, and those are the figures recorded here under the rule preferring the affected party's accounting; the lower published figure is retained as the bound.
Most of the money came back within hours. DODO says that about thirty minutes after being alerted it was aware of crucial movements in the exploit that allowed it to recover almost all of the funds. By its accounting, $3.1 million was returned to affected parties, $300,000 was paid out as a special bounty to those who returned funds, and $200,000 was frozen at an exchange, reducing the net loss to roughly $200,000. Contemporary accounts elsewhere attribute the recovery to arbitrage bots that front-ran the attacker's transactions and captured the tokens first; none of the sources cited here states that, so it is not recorded as established.
DODO states the incident affected only liquidity providers in Crowdpools of a limited number of tokens, and not its main trading pools. No attacker has been publicly identified.
Sources
- DODOPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The DefiantSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.dodoex.io/dodo-recovers-funds-reduces-total-loss-to-200k-304aba695134
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DODO hack — March 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dodohttps://itokenly.com/hacks/dodoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.