T
iTokenly

DODO hack — March 2021

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 9, 2021
Target typeDecentralised exchange
Loss$3,800,000Published estimates range $2,100,000 to $3,800,000Price at time of incident
Recovered$3,100,000
MethodAccess control flawThe init() function on DODO V2 Crowdpooling contracts could be called again on pools that had already been initialised. Re-initialising a live pool let the attacker substitute tokens under their control while the pool still held genuine reserves, and the reserves were then moved out with the help of a flash loan.
ChainsEthereum, BNB Chain
OutcomePartially recovered

What happened

On 9 March 2021 an attacker drained several DODO V2 Crowdpooling pools. DODO's own account attributes the loss to an oversight in the way the Crowdpooling contract's init() function was set up: it could be called again on pools that had already been initialised. CoinDesk described the attack as exploiting the bug to create counterfeit tokens and then moving the real assets out using a flash loan. Contemporary reporting named WSZO, WCRES, ETHA and FUSI as the affected pools. DODO ran contracts on both Ethereum and BNB Chain.

Published figures diverged while the incident was still being analysed. The Defiant reported the loss as $2.1 million and dated the attack to 8 March. CoinDesk reported $3.8 million and said DODO expected just under half of that, $1.88 million, to be returned. DODO's own subsequent accounting settled on $3.8 million taken and on 9 March as the date, and those are the figures recorded here under the rule preferring the affected party's accounting; the lower published figure is retained as the bound.

Most of the money came back within hours. DODO says that about thirty minutes after being alerted it was aware of crucial movements in the exploit that allowed it to recover almost all of the funds. By its accounting, $3.1 million was returned to affected parties, $300,000 was paid out as a special bounty to those who returned funds, and $200,000 was frozen at an exchange, reducing the net loss to roughly $200,000. Contemporary accounts elsewhere attribute the recovery to arbitrage bots that front-ran the attacker's transactions and captured the tokens first; none of the sources cited here states that, so it is not recorded as established.

DODO states the incident affected only liquidity providers in Crowdpools of a limited number of tokens, and not its main trading pools. No attacker has been publicly identified.

Sources

  1. DODOPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. The DefiantSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.dodoex.io/dodo-recovers-funds-reduces-total-loss-to-200k-304aba695134

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "DODO hack — March 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dodo
https://itokenly.com/hacks/dodo

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.