T
iTokenly

Exactly Protocol hack — August 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$7,612,038Published estimates range $7,200,000 to $7,612,038Price at time of incident
MethodReentrancyThe DebtManager periphery contract validated the permit argument rather than the market argument, and because the market was also supplied by the caller the permit check could be bypassed by passing an attacker-deployed contract as the market. That malicious market re-entered crossDeleverage during an external call with msg.sender set to the victim's address, letting the attacker withdraw users' collateral through attacker-controlled Uniswap pools. The attacker also depressed market share value by withdrawing fixed-rate loans, enabling repeated liquidation and extraction cycles.
ChainsOptimism
Audited beforehandExactly's post-mortem states the Market contract had previously been audited by three security companies, which it does not name; ABDK was engaged for the post-incident audit.
OutcomeUsers reimbursed

What happened

Exactly Protocol, a lending market on Optimism, was exploited on 18 August 2023. Its post-mortem records the first attack transaction at 08:46:13 UTC and the protocol paused at 10:40:55 UTC, with all operations except withdrawals disabled. The flaw sat in DebtManager, a periphery contract used for leveraged positions. Its input validation checked the permit argument instead of the market argument, and because the market was also supplied by the caller, the permit check could be bypassed by passing an attacker-deployed contract as the market. That malicious market re-entered crossDeleverage during an external call with msg.sender set to the victim's address, letting the attacker pull collateral out of user positions and route it through attacker-controlled Uniswap pools. The attacker also depressed market share value by withdrawing fixed-rate loans, which enabled repeated liquidation and extraction cycles. About three hours in, a second address began copying the attack. Exactly puts the total at $7,612,038 across 117 accounts, with roughly 4,330 ETH taken by the main attacker, and roughly 140 ETH by the copycat. Independent analyses published lower numbers: Halborn and Neptune Mutual around $7.2 million, and BlockSec and Beosin, cited by The Block and Cointelegraph, about $7.3 million. An initial estimate of more than $12 million circulated on the day and was withdrawn. Proceeds were bridged off Optimism to Ethereum through Across Protocol and the Optimism bridge. Exactly filed a police report and offered a bounty for information. The funds were not recovered. Its governance later passed EXAIP-03, distributing one million EXA tokens, a tenth of total supply, pro rata to the 117 affected accounts, with compensation to be adjusted downward if the stolen assets were recovered before June 2024.

Law enforcement

Exactly filed a police report and offered a bounty for information leading to the attacker. No arrests have been reported.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x3747DbBCb5C07786a4c59883E473A2e38F571af9

Sources

  1. Exactly ProtocolPrimary · retrieved 2026-08-01
  2. Exactly ProtocolPrimary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. The BlockSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/@exactly_protocol/exactly-protocol-incident-post-mortem-b4293d97e3ed

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Exactly Protocol hack — August 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/exactly-protocol
https://itokenly.com/hacks/exactly-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.