T
iTokenly

Roll hack — March 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 14, 2021
Target typeCustodian or payment processor
Loss$5,700,000Price at time of incident
MethodPrivate key compromisePrivate keys to Roll's hot wallet were obtained by an unknown means. Roll stated the compromise was of the key material itself, not a bug in its smart contracts or in any of the social token contracts, and said a week later that it had not identified how the attacker got in; cloud infrastructure logs showed no suspicious logins.
ChainsEthereum
OutcomeUnresolved

What happened

In the early hours of 14 March 2021 an attacker gained control of the private keys to a hot wallet operated by Roll, a platform that issued and held 'social money' tokens on behalf of creators. The wallet held balances of dozens of those tokens.

Roll said the incident was a compromise of the hot wallet's private keys and not a bug in the Roll smart contracts or in any token contract. The attacker sold the tokens into Uniswap for ether and moved the proceeds, roughly 3,000 ETH worth about $5.7 million at the time, into Tornado Cash. Roll's own statement listed 42 affected tokens, including WHALE, FWB, KARMA and JULIEN. Prices of the largest social tokens fell more than 50 percent within hours as the attacker sold into thin liquidity; CoinDesk and Decrypt recorded WHALE, RARE and PICA among them. WHALE's treasury said only 2.17 percent of its supply was compromised because the rest sat in cold storage, and it recovered faster than others. MyCrypto flagged the coordinated selling publicly, at 08:16 UTC, before Roll confirmed it.

Roll suspended withdrawals and engaged a blockchain forensics investigator and law enforcement. A week later chief executive Bradley Miles told TechCrunch the company still did not know how the keys were taken; chief technology officer Sid Kalla said Amazon cloud logs showed no anomalous logins, and Roll's infrastructure, as distinct from its smart contracts, had never been audited before launch.

Roll established a recovery fund for affected creators, initially $500,000 and later raised to $750,000, which it used to buy affected tokens out of Uniswap pools. That is well short of the amount stolen. No arrests have been reported and the funds were not recovered.

Law enforcement

Roll said it engaged a blockchain forensics investigator and contacted law enforcement. No agency has been named publicly and no charges have been reported.

Sources

  1. RollPrimary · retrieved 2026-08-01
  2. TechCrunchSecondary · retrieved 2026-08-01
  3. DecryptSecondary · retrieved 2026-08-01
  4. CoinDeskSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.tryroll.com/p/security-incident-update

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Roll hack — March 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/roll
https://itokenly.com/hacks/roll

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.