T
iTokenly

Odin.fun hack — August 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedAugust 13, 2025
Target typeDecentralised exchange
Loss$7,000,000Price at time of incident
MethodContract logic errorA flaw introduced in an update to the platform's internal automated market maker let an attacker seed pools with effectively worthless platform tokens and self-trade to inflate their bitcoin-denominated price, then withdraw liquidity at the manipulated ratio and take out real bitcoin deposited by other users.
ChainsBitcoin, Other
Attributed toUnidentified actors described by Odin.fun's co-founder as "primarily linked to groups in China"Suspected
OutcomeUnresolved

What happened

Odin.fun, a Bitcoin-based memecoin launchpad, lost 58.2 BTC — about $7 million at the time — in an attack on its internal automated market maker in mid-August 2025. Platform bitcoin deposits fell from 291 BTC to 232.8 BTC in under two hours.

The mechanism was price manipulation inside the AMM rather than an external oracle. PeckShield, which first flagged the drain, and a later technical write-up by QuillAudits describe the attacker depositing effectively worthless tokens, including SATOSHI, into pools alongside BTC and then self-trading to push those tokens' bitcoin-denominated price far above any real market value. Withdrawing liquidity at the manipulated ratio returned far more bitcoin than had gone in. QuillAudits identified the SATOSHI/BTC and ODINPEPE/BTC pools as the ones drained and published two platform account identifiers it attributed to the attacker.

Co-founder Bob Bodily said the flaw had been introduced in the platform's most recent AMM update and blamed "several malicious users, primarily linked to groups in China". No individual or group has been named or charged. Odin.fun halted trading and withdrawals, commissioned an external code audit expected to take about a week, contacted US law enforcement and worked with Binance and OKX. Bodily said the company treasury was not large enough to cover the loss, that remaining platform funds were safe, and that a compensation plan would follow; a public message to the attacker offered "a short window to return the funds".

Sources differ on timing: QuillAudits and several outlets place the drain on 12 August 2025, while The Block and CoinDesk reported it in the early hours of 13 August UTC. No recovery has been reported.

Law enforcement

Odin.fun said it contacted US law enforcement and worked with Binance and OKX, which in turn engaged Chinese authorities. No charges or arrests have been reported.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. QuillAuditsSecondary · retrieved 2026-08-01
  4. DecryptSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Odin.fun hack — August 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/odin-fun
https://itokenly.com/hacks/odin-fun

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.