Loopring hack — June 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 9, 2024 |
| Target type | Wallet software or provider |
| Loss | $5,000,000Price at time of incident |
| Method | Infrastructure compromiseAttackers compromised the AWS-hosted servers running Loopring's centralised two-factor authentication service, using malware traced back to 19 April 2024, and replaced affected users' 2FA contact details with their own. That let them pass verification so the Loopring Official Guardian approved social-recovery requests transferring ownership of the wallets. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 9 June 2024 an attacker took control of Loopring smart wallets by abusing the Official Guardian, the default counterparty in the project's social-recovery scheme. In its post-mortem Loopring said its two-factor authentication server had been compromised: attackers reached AWS servers carrying malware traced back to 19 April 2024, then gained full read and write access and replaced affected users' 2FA data with their own email addresses. That let them pass the verification step, so the Official Guardian approved recovery requests that handed ownership of the wallets to the attacker, who then moved the assets out.
Wallets whose sole guardian was Loopring's own service were the primary exposure, and Loopring said adding independent guardians would have required approvals the attacker did not have. That protection was not absolute. The post-mortem records that wallets with more than one guardian were also compromised, because the second guardian was itself a Loopring Smart Wallet relying on the same default Official Guardian; the report gives the number as four in one passage and says three of the 58 compromised accounts were lost this way in another.
Loopring reported that 58 of more than 40,000 deployed smart wallet addresses lost assets, about 0.14 percent of users. It did not publish a total loss figure. Cyvers put the loss at approximately $5 million after tracking the attacker's address, which held 1,373 ETH once the stolen assets had been converted. The wallets operated on Ethereum and Loopring's zkRollup layer 2.
Loopring paused social recovery and layer-2 services, engaged SlowMist and AWS to investigate, and reintroduced human oversight of every social-recovery operation. The same post-mortem disclosed an earlier and separate April 2024 compromise of layer-1 and layer-2 operator accounts through an administrative key exposed in a secretManager module. Loopring said it reported the theft to Singapore police, who declined it because there were no Singaporean victims and the compromised server was hosted in the United States, and that there was nothing it could do to offset the affected users' losses, though any assets later recovered would be returned to them. No reimbursement, recovery or arrest has been reported.
Law enforcement
Loopring said in its post-mortem that it reported the theft to Singapore police, who declined the case on jurisdictional grounds.
Sources
- LoopringPrimary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- CryptoPotatoSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@byron.loopring/postmortem-incident-report-and-path-forward-aa64f7e5f7d1
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Loopring hack — June 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/loopringhttps://itokenly.com/hacks/loopringPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.