T
iTokenly

Renegade (V1 Arbitrum dark pool) hack — May 2026

Verified — 4 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedMay 10, 2026
Target typeDecentralised exchange
Loss$209,000Price at time of incident
Recovered$190,000
MethodAccess control flawAn unprotected initializer on Renegade's V1 dark-pool proxy let the attacker store its own logic and have the proxy delegatecall it, draining 27 tokens
ChainsArbitrum
OutcomeSettled as bug bounty

What happened

Renegade, a dark-pool exchange, lost about $209,000 from its legacy V1 deployment on Arbitrum on 10 May 2026, in a transaction at 08:27:23 UTC. Renegade said that evening that the issue was isolated to that deployment, that its other deployments were safe, that the whitehat responsible had already returned about $190,000, and that all affected users would be made whole.

According to Blockaid, whose alert Renegade quoted, an unprotected initializer on the dark pool's proxy let the attacker store its own logic in the proxy and have the proxy delegatecall it, draining 27 ERC-20 tokens. DeFiHackLabs notes that the implementation is written in Arbitrum Stylus. Defimon Alerts described the case as "exploit first, negotiate after".

This registry read the receipt: the dark-pool contract sent 27 tokens to the attacker's contract, among them 104,383.59 USDC, 10.28 WETH, 15,471.65 ARB and 0.35 WBTC. Renegade's $209,000 is recorded, with the $190,000 returned recorded as recovered.

Sources

  1. Renegade on XPrimary · retrieved 2026-10-06
  2. Defimon Alerts on XSecondary · retrieved 2026-10-06
  3. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  4. Arbitrum transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Changes to this entry

  • Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Renegade (V1 Arbitrum dark pool) hack — May 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/renegade-v1-arbitrum-may-2026
https://itokenly.com/hacks/renegade-v1-arbitrum-may-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.