Shezmu hack — September 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 20, 2024 |
| Target type | Lending protocol |
| Loss | $4,900,000Price at time of incident |
| Method | Access control flawA Shezmu vault contract exposed an unprotected mint function, letting any caller mint the ShezUSD stablecoin without depositing backing collateral. The attacker deployed a helper contract, minted an effectively unlimited ShezUSD supply and used it to borrow and drain protocol assets, selling into liquidity pools. QuillAudits traced the flaw to a contract upgrade deployed on 3 September 2024. A separate leg against ShezETH, which minted about 9,900 tokens worth roughly $880,000, was attributed by analysts to a possible key leak rather than the same contract bug. |
| Chains | Ethereum |
| Outcome | Settled as bug bounty |
What happened
Shezmu, an Ethereum-based collateralised borrowing protocol that issued the ShezUSD stablecoin against deposited collateral, was drained on 20 September 2024. An attacker found that a Shezmu vault contract left its minting function unprotected, so anyone could mint ShezUSD without supplying backing collateral. The attacker deployed a helper contract, minted an enormous ShezUSD supply and used the tokens to borrow and drain the protocol's assets. Reporting also describes a second leg against ShezETH, in which roughly 9,900 tokens worth about $880,000 were minted; analysts attributed that to a possible key leak rather than to the same contract flaw. Selling the minted tokens also drained an sDAI pool, with MEV bots capturing part of the value.
Published loss estimates cluster at about $4.9 million, and some accounts round the figure to $5 million. QuillAudits linked the vulnerability to a contract upgrade deployed on 3 September 2024.
Shezmu publicly offered the attacker a 10 percent bounty for the return of the remaining 90 percent within 24 hours and said it would not pursue legal action. The attacker countered with 20 percent and Shezmu accepted. The attacker then returned 282.18 ETH, followed by a further 137 WETH. Shezmu's own incident report states that, apart from the agreed bounty, the missing funds were recovered and redistributed to users through migration contracts, an audit, and a Dune Analytics snapshot used to calculate each affected user's share.
Sources
- Shezmu teamPrimary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
- Brave New CoinSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@shezmuteam/shezmu-incident-response-a-journey-to-duat-d9cbaa08298b
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Shezmu hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/shezmuhttps://itokenly.com/hacks/shezmuPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.