MonoSwap hack — July 2024
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | July 24, 2024 |
| Target type | Decentralised exchange |
| Loss | $1,300,000Published estimates range $1,000,000 to $1,300,000Price at time of incident |
| Method | Private key compromiseAttackers posing as venture capital investors persuaded a MonoSwap developer to install an application in order to join a call. The application was infostealer malware, which harvested the private keys held on the developer's office machine. That machine had access to all MonoSwap wallets and contracts, so the attacker gained control of the protocol and withdrew staked liquidity positions. |
| Chains | Blast |
| Outcome | Unresolved |
What happened
MonoSwap, a decentralised exchange on the Blast layer-2 network, announced on 24 July 2024 that it had been compromised. In its own account the team said that "one of our developers installed a phishing app to join a call with scammers who pretended to be a VC. The attackers installed the botnet into his office PC, which has access to all MonoSwap-related wallets and contracts." The application the developer was instructed to install was infostealer malware; Halborn identifies the lure as a program presented as "Kakao". Once it had harvested the private keys, the attacker controlled the wallets and contracts behind the protocol and withdrew staked liquidity positions. MonoSwap told users not to add liquidity or stake in its farming pools and to withdraw any staked positions immediately.
The size of the loss was never confirmed by the project. Crypto Briefing reported at the time that "the exact amount of stolen funds has not been publicly disclosed", and neither Protos nor The Crypto Times gave a figure. Halborn's later write-up put the loss at $1.3 million without stating how the figure was derived. Protos reported that MonoSwap's total value locked fell from roughly $1.5 million to about $200,000 on the day, a decline of approximately $1.3 million, which is consistent with Halborn's number. The $1.3 million figure should therefore be read as a single-source estimate corroborated by the observed drop in TVL, not as an audited or traced total.
Protos also reported that MonoSwap's initial announcement included a link to the attacker's own website, which the team removed after being asked about the wisdom of promoting it. MonoSwap's documentation listed its smart contract audits as "Coming soon", last updated six months earlier.
No funds were recovered, no reimbursement was announced, and no individual or group has been publicly named as responsible.
Sources
- ProtosSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- Web3 is Going Just GreatAggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "MonoSwap hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/monoswaphttps://itokenly.com/hacks/monoswapPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.