dYdX v3 hack — November 2023
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $9,000,000Price at time of incident |
| Method | Oracle or price manipulationCoordinated spot buying across exchanges pushed the index price used by dYdX v3 perpetual markets, inflating 5x leveraged long positions held across ~132 linked accounts; when the manipulated price collapsed the resulting bankrupt positions exceeded their collateral and the v3 insurance fund absorbed the shortfall. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 18 November 2023 dYdX drew more than $9 million from the insurance fund backing its v3 perpetuals exchange to cover shortfalls left by liquidations in the YFI-USD market. That was roughly 40 per cent of the fund, which held about $13.5 million afterwards. Founder Antonio Juliano called it a targeted attack on dYdX, and the company later published a post-mortem setting out what it found.
According to that report, the attacker funded a set of dYdX v3 accounts — 132 were confirmed as connected — and opened 5x leveraged long positions while buying the underlying token on spot markets to push the index price up. The method was first used against SUSHI-USD in late October and early November, when SUSHI rose about 180 per cent from roughly $0.67 to $1.20 and the attacker withdrew unrealised profits as the position grew. dYdX raised the initial margin requirement on that market to 100 per cent and the insurance fund was not touched. The same approach was then applied to YFI-USD from 1 November. Open interest in that market went from $0.8 million to $67 million and YFI rose about 215 per cent, from around $6,500 to over $14,000. When the price fell back the positions were bankrupt and the fund covered the difference.
dYdX said the attacker withdrew approximately $27 million against roughly $16 million deposited, and that they "likely did not profit on dYdX v3 from the price crash of $YFI" itself. Customer funds were not affected. Nothing has been recovered and no charges have been reported.
Law enforcement
dYdX said it identified the attacker, was in contact with them, and was assisting law enforcement in an investigation. No agency has been named, no charges have been reported, and dYdX Trading Inc. said it was assessing legal options.
Sources
- dYdXPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://dydx.exchange/blog/sushi-yfi-incident
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "dYdX v3 hack — November 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/dydx-v3https://itokenly.com/hacks/dydx-v3Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.