T
iTokenly

Dolomite (legacy Ethereum contract) hack — March 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 20, 2024
Target typeDecentralised exchange
Loss$1,800,000Price at time of incident
Recovered$1,620,000
MethodSignature verification flawThe decommissioned 2019 Ethereum product settled trades through Loopring ring-matching contracts, with user approvals held on the Loopring Trade Delegate. Loopring's code returned a non-zero value rather than reverting for orders that were not valid, so an order whose state was coerced to appear filled (order.filledAmountS set to ~uint256(0)) had its signature validation skipped, and invalid orders were never included in rings so escaped further checks. The attacker submitted such invalid orders through submitRingsThroughDyDx alongside two genuine orders, pulling victims' balances into the DolomiteMarginExchange contract and out for a nominal amount of LRC. Cointelegraph described the flaw as a reentrancy-guard bypass; Quantstamp classified it as a token-approval exploit involving insufficient validation.
ChainsEthereum
OutcomeUsers reimbursed

What happened

Dolomite's current markets run on Arbitrum, but a version of the exchange deployed on Ethereum mainnet in 2019 and decommissioned in 2020 was still live on chain. On 20 March 2024 an attacker used it to drain wallets that had never revoked their old token approvals. CertiK flagged the activity publicly, and Dolomite disabled the faulty contract, suspended the legacy system and told users to revoke approvals. Dolomite's post-mortem sets out the mechanism. The legacy product settled trades through Loopring's ring-matching contracts, and users' approvals sat on the Loopring Trade Delegate. Loopring's code returned a non-zero value rather than reverting, so an order whose state was coerced to look filled, with order.filledAmountS set to ~uint256(0), had its signature validation skipped; invalid orders were never included in rings and so escaped further validation. The attacker submitted such invalid orders through submitRingsThroughDyDx alongside two genuine orders, which moved victims' balances into the DolomiteMarginExchange contract and back out in exchange for a nominal amount of LRC. Cointelegraph characterised the flaw as a bypass of a reentrancy guard and Quantstamp grouped it under token-approval exploits caused by insufficient validation; the official account is a skipped signature check. Dolomite recorded 1,245,271 USDC, 94,423 DAI and 165.9 WETH taken from 187 addresses, totalling about $1.8 million. Cointelegraph reported that the proceeds were transferred to an attacker wallet, and deposited into Tornado Cash. Dolomite's post-mortem states that by 15:44:35 UTC on 24 March 2024 it had recovered 90% of the assets taken by the exploiter, without saying how. The treasury covered the remaining 10%, and all victims were repaid on 26 March 2024, with the three restitution transaction hashes published.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x5eAA7DadA44d59549A6c58008b2bd3C7F81d2502

Sources

  1. Dolomite (Corey Caplan)Primary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. QuantstampSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/dolomite-official/legacy-smart-contract-vulnerability-post-mortem-analysis-931d7b555269

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Dolomite (legacy Ethereum contract) hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dolomite
https://itokenly.com/hacks/dolomite

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.