T
iTokenly

MM Finance hack — May 2022

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 4, 2022
Target typeDecentralised exchange
Loss$2,000,000Price at time of incident
MethodSupply chain or frontend compromiseFrontend compromise rather than a contract flaw. MM.Finance said an attacker used a DNS vulnerability to modify the router contract address in its hosted files, so users who traded or removed liquidity through the website while the injected address was live sent their tokens to an attacker-controlled address instead of the exchange router. The contracts themselves were unaffected; only the path to them was poisoned. Filed as supply-chain rather than infrastructure for consistency with the registry's treatment of BadgerDAO and Bybit, where a hijacked user-facing frontend was likewise the attack surface.
ChainsOther
OutcomeUnresolved

What happened

On 4 May 2022 attackers took more than $2 million from users of MM.Finance, at the time the largest decentralised exchange on the Cronos chain. The theft did not involve a smart contract flaw. The site's front end was altered so that the router address user transactions were directed to was replaced with one the attacker controlled; anyone who traded or removed liquidity through the website while the injected address was live sent their tokens to the attacker rather than to the exchange.

The team's own statement was that an attacker used a DNS vulnerability to modify the router contract address in its hosted files. Once the substitution was identified the front end was taken down. Every published account of the mechanism traces back to that self-report; no independent technical post-mortem was produced.

The stolen assets, reported as CRO, were bridged from Cronos to Ethereum via Multichain and passed through Tornado Cash, with part of the flow later traced to OKX. Ethereum was the laundering route, not a venue of the theft. MM.Finance publicly offered the attacker a deal on Twitter, to return 90% of the funds within 48 hours with no questions asked, and said it would involve the FBI if the deadline passed. There is no published confirmation that any funds were returned.

The team said more than $2,000,000 would be compensated and reimbursed, and described funding a compensation pool from its share of trading fees over a 45-day period. Completion of that programme has not been independently confirmed, which is why the outcome is recorded as unresolved rather than as users reimbursed.

The loss has been consistently described as 'more than $2 million' rather than as a precise total. No reconciled accounting of individual victim losses was published, so the figure recorded here is a floor.

Sources

  1. The RecordSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. Crypto BriefingSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "MM Finance hack — May 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/mm-finance
https://itokenly.com/hacks/mm-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.