Gamma Strategies hack — January 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 4, 2024 |
| Target type | Other |
| Loss | $6,180,000Published estimates range $3,400,000 to $6,180,000Price at time of incident |
| Method | Oracle or price manipulationAn arithmetic error in Gamma's automation scripts set the deposit price-deviation guard to a window of -50%/+100% instead of the intended ~2%. The attacker used flash loans from Uniswap and Balancer to move the underlying pool prices inside that widened window, then deposited the inflated assets and received a disproportionate quantity of LP tokens, repeating the sequence across five transactions from block 166,874,977. Attacker address published by Gamma: 0x5351536145610aa448a8bf85ba97c71caf31909c |
| Chains | Arbitrum |
| Outcome | Unresolved |
What happened
Gamma Strategies, a protocol that runs automated liquidity positions on top of decentralised exchanges, was exploited on 4 January 2024 at 03:42 UTC across four vaults on Arbitrum.
Gamma's post-mortem attributes the loss to an arithmetic mistake in its own automation scripts. The scripts were meant to set a deposit guard that rejected deposits when a pool's price had moved more than about 2 percent, but instead configured a window of minus 50 to plus 100 percent. An attacker used flash loans from Uniswap and Balancer to move pool prices well inside that widened window, then deposited the inflated assets and received a disproportionate quantity of LP tokens, repeating the sequence across five transactions.
The published figures differ substantially. PeckShield and BlockSec, who first flagged the attack, put the loss at roughly $3.4 million, or over 1,500 ETH, and that figure carried through most contemporaneous reporting. Gamma's own accounting, published afterwards, totalled about $6.18 million across the four vaults: roughly $2.74 million from a gDAI-DAI Uniswap vault, $1.36 million from a USDT-USDC.e Camelot vault, $1.31 million from a USDC-USDC.e Ramses vault and $771,000 from a wstETH-WETH Camelot vault. BlockSec's founder described the underlying issue as an inconsistency between how deposits and withdrawals were accounted for.
Gamma sent an on-chain message to the attacker's address proposing a bug bounty settlement. No funds were returned. The protocol suspended deposits while leaving withdrawals open, commissioned an external code review, and set up a recovery pool for affected users funded from protocol revenue plus $120,000 of company reserves, projecting full repayment in around 1.7 years. The attacker has not been identified.
Sources
- Gamma StrategiesPrimary · retrieved 2026-08-01
- The CryptonomistSecondary · retrieved 2026-08-01
- CryptonewsSecondary · retrieved 2026-08-01
Official post-mortem: https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Gamma Strategies hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gamma-strategieshttps://itokenly.com/hacks/gamma-strategiesPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.