T
iTokenly

SushiSwap hack — April 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 9, 2023
Target typeDecentralised exchange
Loss$3,300,000Price at time of incident
MethodContract logic errorThe newly deployed RouteProcessor2 router accepted route parameters from the caller without adequate validation, so an attacker could supply an address of their choosing and have the contract move any token a victim had approved to it. The contract was non-upgradeable, could not be paused, and offered no way to revoke approvals on users' behalf.
ChainsMultiple chains
OutcomeUsers reimbursed

What happened

In the early hours of 9 April 2023 an approval bug in SushiSwap's RouteProcessor2 router was used to drain funds from users who had granted the contract token approvals. PeckShield put the loss at more than $3.3 million, roughly 1,800 ETH. The largest single victim was one pseudonymous trader's wallet, from which about 1,800 WETH was taken. Sushi's own post-mortem dates the incident to 8 April; Cointelegraph and CryptoSlate both place it on 9 April, and that date is used here.

Sushi had soft-launched the V3 router shortly before. The contract handled caller-supplied route parameters without adequate validation, letting an attacker direct it at an address of their choosing and have it move any token a victim had approved. Sushi's post-mortem notes the contract was non-upgradeable, could not be paused, and gave the team no way to revoke access for users, so the only immediate remedy was for users to revoke approvals themselves. Head developer Jared Grey posted that warning publicly, saying the team was working with security teams to mitigate the issue.

RouteProcessor2 was deployed on 14 networks - Arbitrum, Arbitrum Nova, Avalanche, Boba, BSC, Ethereum, Fantom, Fuse, Gnosis, Moonbeam, Moonriver, Optimism, Polygon and Polygon zkEVM - and affected users were spread across them. Security firm HYDN ran a whitehat rescue that Sushi's post-mortem credits with saving over $750,000 of user funds, and for which HYDN was awarded $200,000. Sushi reported 885 ETH recovered in total, said about 795 ETH of the stolen funds had been dispersed as rewards through Lido's execution-layer rewards vault, and said 94.9 ETH remained in an attacker-controlled address. CryptoSlate reported earlier partial returns of 90 ETH by one address and 100 ETH rescued by BlockSec.

Sushi opened a Merkle-based claim portal to return rescued assets one-for-one and said it would review remaining losses case by case and cover them.

Sources

  1. SushiPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. CryptoSlateSecondary · retrieved 2026-08-01

Official post-mortem: https://www.sushi.com/blog/routeprocessor2-post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SushiSwap hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/sushiswap
https://itokenly.com/hacks/sushiswap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.