NowSwap hack — September 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 15, 2021 |
| Target type | Decentralised exchange |
| Loss | $1,000,000Price at time of incident |
| Method | Contract logic errorAn incomplete constant update left one of three checks on the constant-product invariant validating a tenth of the correct value, so the pair contract accepted a trivial input, reported as little as 1 wei, in exchange for almost the whole pool balance. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 15 September 2021 an attacker emptied the liquidity pools of NowSwap, an Ethereum decentralised exchange built on the Uniswap V2 model. Two security firms flagged the transactions the same day: PeckShield, cited by CoinGape, and BlockSec, cited by CoinChapter. Both put the take at roughly 535,700 USDT and about 158 WETH and described the total as more than $1 million. No precise dollar total was published by the protocol or by an independent analyst, so the figure recorded here is the reported floor rather than a settled valuation.
The cause was a botched constant update. The pair contract's constant-product invariant, referred to in the code as K, appeared in three places with a value of 1,000. When that value was changed, two occurrences were updated and the third was not. The one left behind was the check that validates the invariant after a swap, so the contract enforced only a tenth of the correct constraint. That let the attacker submit a negligible input, reported as low as 1 wei, and withdraw close to the entire balance held in the pool.
The identical mistake had produced the Uranium Finance loss five months earlier. Analysts also noted that NowSwap's contracts were not open source, which limited independent review beforehand.
The stolen USDT was routed through the 1inch aggregator into ETH and then through Tornado Cash. NowSwap said it was investigating the attack. No post-mortem, reimbursement plan or recovery followed, and no attribution has been made.
Sources
- CoinChapterSecondary · retrieved 2026-08-01
- CoinGapeSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "NowSwap hack — September 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nowswaphttps://itokenly.com/hacks/nowswapPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.