T
iTokenly

Steadefi hack — August 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedAugust 7, 2023
Target typeLending protocol
Loss$1,140,000Price at time of incident
MethodPrivate key compromiseThe private key to Steadefi's deployer wallet, which owned every contract the project had deployed, was compromised. The attacker transferred ownership of the lending and strategy vaults to their own addresses and then used owner-only functions to lend out the entire available balance of the lending vaults to themselves.
ChainsArbitrum, Avalanche
OutcomeUnresolved

What happened

Steadefi, a leveraged yield-farming protocol running on Arbitrum and Avalanche, announced on 7 August 2023 that it had been exploited. Its post on X read: "NOTICE: Steadefi has been exploited and all funds are currently at risk." Coin Edition reported the loss at $1.14 million; Halborn put it at over $1.1 million.

No contract logic was broken. The attacker obtained the private key to Steadefi's deployer wallet, which was the owner of every contract the project had deployed. With that key they transferred ownership of the lending and strategy vaults to addresses they controlled, then used owner-only functions to lend out the full available balance of the lending vaults to themselves, taking WBTC, WETH and USDC. The proceeds were swapped into ETH and bridged to Ethereum. The attacker also paused a number of the protocol's contracts, which trapped funds inside and blocked users from withdrawing while the incident was being handled. Steadefi said that its depositor and strategy vaults did not expose the same privileged function and that assets held there were not taken; that account comes from the project itself and is not independently corroborated by the security analyses of the incident.

Steadefi sent an on-chain message offering the attacker a 10% bounty and an undertaking not to pursue legal action if the remainder was returned by 08:00 UTC on 10 August 2023, saying the offer would be opened to the public if the deadline passed. No public accounting of a return or recovery has been located, and no one has been identified or charged.

Some accounts date the incident to 8 August; Steadefi's own announcement was posted at 18:33 UTC on 7 August.

Sources

  1. SteadefiPrimary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. Coin EditionSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Steadefi hack — August 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/steadefi
https://itokenly.com/hacks/steadefi

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.