T
iTokenly

Dough Finance hack — July 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 12, 2024
Target typeLending protocol
Loss$2,100,000Published estimates range $1,800,000 to $2,500,000Price at time of incident
MethodContract logic errorUnvalidated calldata in the ConnectorDeleverageParaswap contract. The deleveraging path (executeOperation -> deloopInOneOrMultipleTransactions -> deloopAllCollaterals) took a flash loan and then forwarded caller-supplied calldata to an external swap contract without validating the target or the payload anywhere in the chain. The attacker substituted calldata that made the connector call transferFrom on WETH, moving users' tokens directly out of the contract across eight transactions.
ChainsEthereum
Attributed toAttacker address 0x67104175fc5fabbdb5A1876c3914e04B94c71741 (identified by CertiK); operator unidentifiedUnknown
OutcomePartially recovered

What happened

Dough Finance, an Ethereum protocol offering leveraged "looping" strategies built on top of Aave, was drained on 12 July 2024. The bug sat in ConnectorDeleverageParaswap, the contract that unwound leveraged positions. Its deleveraging path took a flash loan and then forwarded caller-supplied calldata to an external swap contract without validating it. CertiK's analysis found no validation anywhere in the call chain, which allowed an attacker to substitute calldata that made the connector call transferFrom on WETH and move user tokens straight out. Eight transactions were used. CertiK identified the attacker address. Published totals differ. Contemporary reports measuring the attacker's proceeds gave 608 ETH, about $1.8 million; CertiK's transaction-level analysis put the loss at roughly $2.1 million; Cointelegraph later described it as about $2.5 million. Dough Finance never published its own accounting, so the figure remains contested. The attacker, funded through Railgun, converted the stolen USDC into ETH and sent 600 ETH to Tornado Cash the following day. A white-hat address returned 69.12 ETH and the MEV bot c0ffeebabe.eth returned 7.05 ETH. Dough Finance posted an on-chain message giving the attacker until 23:00 UTC on 15 July 2024 to make contact before pursuing criminal and civil action; no return followed. The team announced a recovery plan based on a governance vote to redistribute recovered funds, compensation tokens and a burn-and-redeem mechanism. Cointelegraph reported in 2026 that the vote was never held, the tokens were never usable, and affected users received roughly $281,000 in total.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x67104175fc5fabbdb5A1876c3914e04B94c71741

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. DailyCoinSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Dough Finance hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dough-finance
https://itokenly.com/hacks/dough-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.