MonoX Finance hack — November 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $31,000,000Price at time of incident |
| Method | Contract logic errorswap accepted the same token as tokenIn and tokenOut; the tokenOut price write overwrote the tokenIn write, inflating MONO |
| Chains | Ethereum, Polygon |
| Audited beforehand | MonoX said it completed three audits before launch; Crypto Briefing named PeckShield and Halborn as prior auditors. Neither audit caught the same-token swap case. |
| Outcome | Unresolved |
What happened
MonoX Finance was an automated market maker that used a single-sided pool model, with deployments on Ethereum and Polygon. On 30 November 2021 an attacker drained both for about $31 million.
The bug was in the swap path. The contract did not reject a swap in which the input token and the output token were the same. When the attacker repeatedly swapped the protocol's MONO token for itself, prices were verified independently for each side and the output token was written last, so that write overwrote the price update for the input token. Each pass ratcheted MONO's recorded price upward without the attacker spending anything. Once MONO was valued arbitrarily high, it was used to buy out the rest of the pools' assets.
By the breakdown reported at the time, about $18.2 million of wrapped ether and about $10.5 million of MATIC were taken, along with smaller amounts of wrapped bitcoin, Chainlink, Unit Protocol, Aavegotchi and Immutable X.
In its post-mortem the team said 406 addresses were affected on Ethereum and 15,523 on Polygon, of which 42 and 2,653 respectively were actively providing liquidity. It said the protocol had been through three audits before launch; Crypto Briefing named PeckShield and Halborn as prior auditors, neither of which had flagged the same-token case. Chief executive Ruyi Ren said the team was trying to reach the attacker.
The team reported that 100 ETH of the proceeds had been sent to Tornado Cash while the remainder sat unmoved, pointed to a $1 million policy from Tidal as partial cover, and said a compensation plan would follow and the contracts would not be redeployed without another audit. No recovery has been confirmed.
Sources
- MonoX TeamPrimary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- Schneier on Security (crediting Ars Technica)Secondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/monoswap/exploit-post-mortem-33921a779b43
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "MonoX Finance hack — November 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/monox-financehttps://itokenly.com/hacks/monox-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.