Furucombo hack — February 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 27, 2021 |
| Target type | Other |
| Loss | $15,000,000Published estimates range $14,000,000 to $15,000,000Price at time of incident |
| Method | Access control flawFurucombo's proxy contract used a single whitelist covering both permitted callers and permitted call targets, and the Aave V2 lending pool proxy was on that list. The attacker called batchExec to make Furucombo delegatecall into the Aave V2 proxy and invoke its initialize function, which set the attacker's own contract as the implementation within Furucombo's storage context. A second batchExec call then chained Furucombo into the Aave proxy and on into the attacker's contract, which called transferFrom against every wallet that still had ERC-20 approvals outstanding on the Furucombo proxy. The losses therefore fell on users' own balances rather than protocol reserves. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
Furucombo, an Ethereum tool that let users chain together actions across DeFi protocols in a single transaction, was drained on 27 February 2021 at 16:47 UTC.
The protocol worked through a proxy contract that users granted token approvals to. That proxy maintained one whitelist covering both which contracts could call it and which contracts it could call, and the Aave V2 lending pool proxy was on the list. The attacker used Furucombo's batchExec function to delegatecall into the Aave proxy and invoke its initialize function, setting the attacker's own contract as the implementation inside Furucombo's storage context. A second call then routed Furucombo into the Aave proxy and on into the attacker's contract, which called transferFrom against every wallet still holding open approvals on Furucombo.
Because the theft hit users' own balances rather than protocol reserves, the damage was concentrated. Furucombo's post-mortem counted 22 affected users and 21 different assets. Furucombo put the total at $15 million; contemporaneous reporting used a $14 million figure drawn from early estimates, and the precise number is uncertain because the attacker moved the proceeds into Tornado Cash in instalments.
Furucombo removed the Aave V2 component from its registry, upgraded the proxy and registry contracts, and told users to revoke outstanding approvals. Victims were compensated not with returned assets but with 5 million rCOMBO claim tokens drawn against a recovery pool of 5 million COMBO, vesting linearly over 360 days from 1 March 2021. The attacker was never identified and none of the stolen funds were recovered.
Sources
- FurucomboPrimary · retrieved 2026-08-01
- FurucomboPrimary · retrieved 2026-08-01
- cmichel (Christoph Michel)Secondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/furucombo/furucombo-post-mortem-march-2021-ad19afd415e
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Furucombo hack — February 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/furucombohttps://itokenly.com/hacks/furucomboPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.