T
iTokenly

Merlin DEX hack — April 2023

Verified — 6 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 26, 2023
Target typeDecentralised exchange
Loss$1,820,000Published estimates range $1,820,000 to $2,000,000Price at time of incident
Recovered$160,000
MethodRug pull or exit scamThe pair contracts' initialize function granted the deployment-controlled "feeTo" address an unlimited allowance over both pool tokens, so whoever held that key could call transferFrom and move all deposits out of any liquidity pool. Described by CertiK as a private key management issue and later as a rug pull by rogue developers rather than an external exploit.
ChainsOther
Audited beforehandCertiK
Attributed toUnnamed Merlin back-end developersSuspected
OutcomePartially recovered

What happened

Merlin was a decentralised exchange on zkSync Era that had been audited by CertiK days earlier. On 26 April 2023, during a three-day Liquidity Generation Event for its MAGE token, its liquidity pools were emptied.

The mechanism was a privilege built into the pair contracts rather than an external bug. The initialize function granted the deployment-controlled "feeTo" address an unlimited allowance over both pool tokens, so whoever held that key could call transferFrom and move user deposits out of any pool. The zkSync DEX eZKalibur published the two lines of code responsible. CertiK said its initial findings pointed to a private key management issue rather than an exploit, said it had raised private key privilege issues in its audit report, and later described the event as a rug pull carried out by developers with privileged access rather than an outside attack. CertiK said the rogue developers were believed to be based in Europe, and subsequently in Serbia, and that it was working with law enforcement. No one has been charged and the individuals have not been publicly named.

Figures differ. The Block and Decrypt reported the loss as $1.82 million on the basis of on-chain evidence; CertiK repeatedly described "around $2 million" when discussing compensation. CryptoSlate reported that 402 ETH, then worth about $783,195, had been traced to a single wallet. CertiK offered the developers a 20% white-hat bounty, said on 4 May 2023 that it had frozen roughly $160,000 of the stolen funds with the help of partners, and said it was discussing a community compensation plan with zkSync.

Law enforcement

Merlin said it notified authorities in Serbia; CertiK said it was working with law enforcement to trace developers it believed were based in Europe.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. DecryptSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. UnchainedSecondary · retrieved 2026-08-01
  5. CryptoSlateSecondary · retrieved 2026-08-01
  6. crypto.newsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Merlin DEX hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/merlin-dex
https://itokenly.com/hacks/merlin-dex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.