T
iTokenly

Seneca Protocol hack — February 2024

Verified — 6 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 28, 2024
Target typeLending protocol
Loss$6,400,000Price at time of incident
Recovered$5,300,000
MethodAccess control flawThe Chamber contract's public performOperations() function accepted an action code plus arbitrary calldata and a target address, and forwarded the call without validating either. Passing action code 30 (OPERATION_CALL) reached an internal _call(), which the attacker used to make Chamber invoke transferFrom() on ERC-20 tokens that users had previously approved to Chamber, moving those tokens out of the victims' own wallets. Pause/unpause were declared internal, so the team could not stop the contracts mid-drain.
ChainsEthereum, Arbitrum
Audited beforehandYes
OutcomeSettled as bug bounty

What happened

On 28 February 2024 an attacker drained roughly $6.4 million, mostly in ether, from wallets that had granted token approvals to Seneca's Chamber contracts on Ethereum and Arbitrum. Seneca operated a collateralised debt position system that issued the senUSD stablecoin.

The Chamber contract exposed a public function, performOperations(), which took an action code and arbitrary call data and then forwarded that call to any address the caller specified, with no validation of the target or the payload. The attacker used it to make the Chamber contract call transferFrom() on tokens users had already approved to Chamber, sending them from the victims' wallets to an address the attacker controlled. Assets deposited into Seneca's own vaults and staking contracts were not touched; the losses fell on users holding live approvals. A second defect made things worse: the pause and unpause functions were declared internal, so the team could not halt the contracts while the drain ran. That was flagged by researcher ddimitrov22 and reported by Cointelegraph, which also cited CertiK and the investigator Spreek. CryptoPotato reported that researcher Daniel Von Fange had raised the flaw before the attack and was removed from the project's Discord, and quoted Seneca saying the deployed Chamber code matched the audited code apart from fixes the auditor requested.

Seneca posted an on-chain message on 29 February offering a 20 percent bounty for the return of the funds and warning of legal action. Within hours the attacker returned 1,537 ETH, about $5.3 million, and kept 300 ETH, about $1 million, split across two addresses. Published loss figures cluster at $6.4 million, equivalent to more than 1,900 ETH plus 50,000 senUSD; some technical write-ups round it to "over $6 million".

Law enforcement

Seneca said publicly that it was working with third-party security providers and law enforcement to trace the funds. No agency was named and no case has been publicly identified.

Sources

  1. Seneca ProtocolPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. CyfrinSecondary · retrieved 2026-08-01
  5. BlockApexSecondary · retrieved 2026-08-01
  6. CryptoPotatoSecondary · retrieved 2026-08-01

Official post-mortem: https://mirror.xyz/0x289D0033d536eb3Ff53367f0A8CceA00d4Ac63a0/_VPi_1T8CWsnQctOA4Z8WS8jKc2B6lIV0hPcQ2Kb-c4

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Seneca Protocol hack — February 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/seneca-protocol
https://itokenly.com/hacks/seneca-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.