T
iTokenly

Sunray Finance hack — October 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedOctober 30, 2024
Target typeDecentralised exchange
Loss$2,850,000Published estimates range $2,700,000 to $2,885,000Price at time of incident
MethodPrivate key compromiseA compromised owner key was used to upgrade the project's administrative contract in a single transaction to a version permitting unlimited minting, according to CertiK Alert. A very large quantity of SUN tokens was then minted and immediately swapped against the project's own liquidity, draining the SUN and ArcToken treasuries into roughly 2.1 million USDT and about $750,000 of WETH.
ChainsArbitrum
OutcomeUnresolved

What happened

On or about 30 October 2024 the treasury of SUNRAY FINANCE, a pre-launch decentralised exchange and perpetuals project on Arbitrum, was emptied after its administrative contract was upgraded to a version that permitted unlimited token minting. A very large quantity of SUN tokens was created and immediately swapped against the project's own liquidity, which was drained into stablecoins. Sources differ on the quantity minted: Cryptopolitan reports roughly 200 trillion SUN, while the Quadriga Initiative case study puts it at two hundred sextillion.

Cryptopolitan traced the proceeds as more than 2.1 million USDT plus about $750,000 in WETH, and reported that the attacker's initial wallet had been funded from Ethereum through the Across bridge before the upgrade transaction. Published totals range from $2.7 million to $2.885 million: Cryptopolitan headlines $2.8 million and notes an initial $2.7 million report, while the Quadriga Initiative case study headlines $2.885 million and also records $2.855 million. SUN fell to zero and the ArcToken (ARC) treasury was affected as well.

On the cause, CertiK Alert, relayed by ChainCatcher, said the project's private key had been leaked and that the attacker thereby gained ownership of the SUN and ARC token contracts. Cryptopolitan's account focuses on the mechanics of the upgrade, describing it as executed in a single transaction followed by swaps in the next blocks, without addressing how the attacker obtained the authority to upgrade. No published source identifies who held the key, no evidence distinguishing an external compromise from insider use has been produced, and no charges have been brought.

Sunray Finance's own account acknowledged the movement of SUN and ArcToken treasury assets and said it was working to restore the position. No recovery has been reported, and the incident appears to have ended the planned launch of the exchange.

Sources

  1. CryptopolitanSecondary · retrieved 2026-08-01
  2. ChainCatcher (reporting CertiK Alert)Secondary · retrieved 2026-08-01
  3. Quadriga InitiativeAggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Sunray Finance hack — October 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/sunray-finance
https://itokenly.com/hacks/sunray-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.