Dough Finance hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 12, 2024 |
| Target type | Lending protocol |
| Loss | $2,100,000Published estimates range $1,800,000 to $2,500,000Price at time of incident |
| Method | Contract logic errorUnvalidated calldata in the ConnectorDeleverageParaswap contract. The deleveraging path (executeOperation -> deloopInOneOrMultipleTransactions -> deloopAllCollaterals) took a flash loan and then forwarded caller-supplied calldata to an external swap contract without validating the target or the payload anywhere in the chain. The attacker substituted calldata that made the connector call transferFrom on WETH, moving users' tokens directly out of the contract across eight transactions. |
| Chains | Ethereum |
| Attributed to | Attacker address 0x67104175fc5fabbdb5A1876c3914e04B94c71741 (identified by CertiK); operator unidentifiedUnknown |
| Outcome | Partially recovered |
What happened
Dough Finance, an Ethereum protocol offering leveraged "looping" strategies built on top of Aave, was drained on 12 July 2024. The bug sat in ConnectorDeleverageParaswap, the contract that unwound leveraged positions. Its deleveraging path took a flash loan and then forwarded caller-supplied calldata to an external swap contract without validating it. CertiK's analysis found no validation anywhere in the call chain, which allowed an attacker to substitute calldata that made the connector call transferFrom on WETH and move user tokens straight out. Eight transactions were used. CertiK identified the attacker address. Published totals differ. Contemporary reports measuring the attacker's proceeds gave 608 ETH, about $1.8 million; CertiK's transaction-level analysis put the loss at roughly $2.1 million; Cointelegraph later described it as about $2.5 million. Dough Finance never published its own accounting, so the figure remains contested. The attacker, funded through Railgun, converted the stolen USDC into ETH and sent 600 ETH to Tornado Cash the following day. A white-hat address returned 69.12 ETH and the MEV bot c0ffeebabe.eth returned 7.05 ETH. Dough Finance posted an on-chain message giving the attacker until 23:00 UTC on 15 July 2024 to make contact before pursuing criminal and civil action; no return followed. The team announced a recovery plan based on a governance vote to redistribute recovered funds, compensation tokens and a burn-and-redeem mechanism. Cointelegraph reported in 2026 that the vote was never held, the tokens were never usable, and affected users received roughly $281,000 in total.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0x67104175fc5fabbdb5A1876c3914e04B94c71741
Sources
- CertiKSecondary · retrieved 2026-08-01
- DailyCoinSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Dough Finance hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dough-financehttps://itokenly.com/hacks/dough-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.