T
iTokenly

Level Finance hack — May 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 1, 2023
Target typeDecentralised exchange
Loss$1,010,000Published estimates range $1,010,000 to $1,100,000Price at time of incident
MethodContract logic errorThe claimMultiple() function of LevelReferralControllerV2 did not check whether a reward epoch had already been claimed, so passing the same epoch repeatedly added a further payout each time. The attacker first inflated their referral tier using multiple referral accounts and flash-loaned swaps.
ChainsBNB Chain
OutcomeUnresolved

What happened

On 1 May 2023 an attacker drained the referral rewards contract of Level Finance, a decentralised perpetual trading protocol on BNB Chain. The flaw sat in LevelReferralControllerV2: the claimMultiple() function did not verify that a reward epoch had already been claimed, so the same epoch could be submitted repeatedly and each submission added another payout to the running total. Before claiming, the attacker inflated their referral tier; published analyses describe the use of multiple referral accounts and flash-loaned swaps to reach a higher reward band.

PeckShield, which flagged the transactions publicly on the day, put the take at roughly 214,000 LVL tokens, swapped into 3,345 BNB. Cointelegraph valued that at about $1.01 million. Halborn and several other outlets described the loss as about $1.1 million. No party published a reconciliation of the two figures, and Level Finance never gave a dollar total of its own.

Level Finance confirmed the incident the same day, saying the exploit had targeted its Referral Controller Contract, that liquidity pools and the DAO treasury were unaffected, and that a fix would be deployed within twelve hours. The referral program was suspended to stop further claims and a replacement contract was deployed. Halborn's analysis reported that the same exploit had been attempted about a week earlier, and that the bug had been overlooked in security auditing, without naming the firm involved.

The stolen BNB was not returned. No arrests, charges or attribution have been reported, and the full technical post-mortem the team said it would publish did not appear.

Sources

  1. CointelegraphSecondary · retrieved 2026-08-01
  2. SolidityScanSecondary · retrieved 2026-08-01
  3. PeckShieldSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Level Finance hack — May 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/level-finance
https://itokenly.com/hacks/level-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.