Saddle Finance hack — April 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 30, 2022 |
| Target type | Decentralised exchange |
| Loss | $10,000,000Published estimates range $10,000,000 to $13,800,000Price at time of incident |
| Recovered | $3,800,000 |
| Method | Contract logic errorThe sUSD metapool's swap path from an underlying token to LP tokens omitted the base pool's virtual price, mispricing LP tokens; exploited with a flash loan across three transactions |
| Chains | Ethereum |
| Outcome | Partially recovered |
What happened
Saddle Finance, an Ethereum stableswap AMM, was exploited on 30 April 2022 at about 07:40 UTC. The bug lay in its sUSD metapool: Saddle had reimplemented Curve's metapool maths in Solidity rather than using the original Vyper code, and the swap path exchanging an underlying token for pool LP tokens failed to apply the base pool's virtual price. Immunefi locates the defect in the MetaSwapUtils library, which omitted the base virtual price during swap calculations even though the deposit and withdrawal paths handled it correctly. LP tokens were therefore mispriced against the assets backing them.
According to Immunefi's technical write-up, the attacker took a flash loan of USDC, swapped it for sUSD on Curve, then cycled sUSD into and out of Saddle LP tokens to harvest the pricing gap before repaying the loan.
BlockSec's monitoring system observed the attacker calling the same function three times. The first call succeeded; the second failed on insufficient gas at block 14684432, which BlockSec's Phalcon system detected; BlockSec then sent its own transaction at block 14684434, pre-empting the third attempt and extracting 1,360 ETH — about $3.8 million at the time — which Saddle confirmed it was in the process of recovering from BlockSec. Of the roughly 4,900 ETH (about $13.8 million) that left the pools, the attacker kept around 3,540 ETH, which The Block and others reported as a loss of just over $10 million. Immunefi's later analysis described roughly $11 million as taken and put the whitehat share at about 25 per cent, a figure that does not reconcile with BlockSec's $3.8 million.
The figure recorded here is the net loss after the BlockSec rescue; the gross outflow from the pools was higher. The incident is frequently cited as the first case of an attack-detection system front-running a live exploit to rescue funds. No attribution or arrests have been reported.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Saddle Finance hack — April 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/saddle-financehttps://itokenly.com/hacks/saddle-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.