Sovryn hack — October 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 4, 2022 |
| Target type | Lending protocol |
| Loss | $1,100,000Published estimates range $1,100,000 to $1,200,000Price at time of incident |
| Method | ReentrancyCross-contract reentrancy in the iRBTC and iUSDT lending pools. When a loan was closed by swapping collateral, the pool's internal state was updated before the underlying asset had arrived, briefly under-pricing its iTokens. Using the callback fired during that swap, the attacker minted iTokens at the discounted price and redeemed them once funds landed. Financed with a flash swap of WRBTC and routed through the closeWithDeposit function. |
| Chains | Other |
| Outcome | Users reimbursed |
What happened
Sovryn is a lending and margin-trading protocol on Rootstock, a Bitcoin sidechain. On 4 October 2022 an attacker took funds from two of its lending pools in two waves, at about 01:30 and 02:56 UTC. Sovryn's post-mortem describes a cross-contract reentrancy, which it distinguishes from classical same-contract reentrancy. When a loan was closed by swapping collateral, the protocol updated its internal state before the underlying asset had actually arrived in the lending pool, so for a moment the pool's iTokens were priced too low. Using a callback fired during that swap, the attacker minted iTokens at the discounted price and redeemed them once the funds landed, keeping the difference. The iRBTC and iUSDT pools were affected. Independent analyses by SolidityScan and Halborn describe the same sequence, financed with a flash swap of WRBTC and routed through the closeWithDeposit function; SolidityScan gives the attacker address, one of five addresses Sovryn publicly linked to the attack. The loss was reported at the time as about $1.1 million. The token accounting differs between Sovryn's own statements: its interim update listed 44.93 RBTC and 211,045 USDT, while the final post-mortem itemises 44.9368 RBTC and 282,351.96 rUSDT. Contemporary reporting valued the RBTC leg at roughly $915,000. Sovryn said developers recovered about half the value, listing 17.717 RBTC, 19,511 USDT, 26.761 ETH and 60.85 BNB; SolidityScan reported the remaining proceeds were laundered through Tornado Cash. All funds removed from the lending pools were returned, with the balance covered by the Sovryn treasury, so lenders were made whole. A fix was deployed on 24 October 2022. No actor has been identified and no charges have been reported.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xc92ebecda030234c10e149beead6bba61197531a
Sources
- SovrynPrimary · retrieved 2026-08-01
- SovrynPrimary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- CryptoDailySecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://sovryn.com/all-things-sovryn/october-2022-lending-pool-exploit-postmortem
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Sovryn hack — October 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/sovrynhttps://itokenly.com/hacks/sovrynPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.