T
iTokenly

Swaprum hack — May 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 19, 2023
Target typeDecentralised exchange
Loss$3,000,000Published estimates range $2,960,000 to $3,000,000Price at time of incident
MethodRug pull or exit scamThe deployer account upgraded the protocol's MasterChef-style staking proxy to an unaudited implementation in which the add() function moved user-staked LP tokens out of the contract and removed the underlying liquidity, and an added getToken() function allowed unrestricted minting of the SAPR token, which was then sold.
ChainsArbitrum
Audited beforehandCertiK
Attributed toSwaprum's own deployer/operators (unidentified)Suspected
OutcomeUnresolved

What happened

On 18 May 2023 the deployer account behind Swaprum, a decentralised exchange on Arbitrum forked from Arbiswap, used the upgradeability of the protocol's MasterChef-style staking contract to replace its implementation with unaudited code. In the substituted version the add() function, normally used to register a new staking pool, instead moved LP tokens that users had staked into the farm out of the contract and removed the underlying liquidity. A second added function, getToken(), allowed unrestricted minting of the project's SAPR token, which was then sold.

PeckShield traced roughly 1,628 ETH out of the protocol and reported that about 1,620 ETH was routed through Tornado Cash. Decrypt, citing PeckShield, put the loss at about $3 million, and CertiK's own write-up also used $3 million, while accounting for 1,628 ETH at the day's price puts it nearer $2.96 million. SAPR fell to zero and the team deleted its social media accounts, though the website remained online for a period.

Swaprum carried an "audited by CertiK" badge; CertiK had published its report on 5 May 2023, thirteen days before the incident. CertiK said afterwards that it had flagged heavy centralisation and contract upgradeability, and that the malicious implementation fell outside the audited scope because it was deployed after the audit. The firm was criticised for this, notably by TradingStrategy.ai co-founder Mikko Ohtamaa, who compared it to the Merlin DEX rug pull the previous month.

No arrests have been reported and the funds were not recovered. Nobody has been charged; the attribution to the project's own operators rests on the fact that the deployer key performed the upgrade, as described by CertiK and PeckShield.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. DecryptSecondary · retrieved 2026-08-01
  3. Web3 Is Going GreatAggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Swaprum hack — May 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/swaprum
https://itokenly.com/hacks/swaprum

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.