Team Finance hack — October 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 27, 2022 |
| Target type | Other |
| Loss | $14,500,000Published estimates range $14,500,000 to $15,800,000Price at time of incident |
| Method | Contract logic errorThe migrate function on Team Finance's Liquidity Locks contract, used to move locked positions from Uniswap v2 to Uniswap v3, did not properly validate the token pair it was asked to move. By first locking a token of their own to the contract, the attacker bypassed the validation and caused real v2 liquidity to be moved into an attacker-controlled v3 pair priced at a ratio they had set; the difference between the deposited liquidity and the value of the position minted in the skewed pair was refunded to the attacker. |
| Chains | Ethereum |
| Audited beforehand | Zokyo Security |
| Outcome | Unresolved |
What happened
On 27 October 2022 an attacker exploited Team Finance, an Ethereum service that locks liquidity pool tokens on behalf of token projects, through a feature that migrated locked positions from Uniswap v2 to Uniswap v3.
The migrate function on the Liquidity Locks contract did not properly validate what it was being asked to move. By first locking a token of their own to the contract, the attacker got past the validation and had the contract move real v2 liquidity into a v3 pair they controlled, priced at a ratio they had set. The gap between the liquidity deposited and the value of the position minted in the skewed pair was refunded to the attacker, who kept the difference. PeckShield put the cost of the initial attack transaction at about 1.76 ETH, roughly $1,600 at the time. Assets drained included DAI, USDC and ETH along with the tokens of projects that had locked liquidity with the service, among them CAW, TSUKA and KNDA.
Figures differ. Team Finance said $14.5 million of tokens were taken through the migration function. PeckShield's on-chain analysis later put the total at $15.8 million, including about $6.43 million in DAI and $1.3 million in ETH. The contract had been audited by Zokyo Security, whose auditors had raised concern about passing arbitrary addresses to the lockTokens function, which performs external calls, but did not identify the flaws that were used.
Team Finance paused the platform, said remaining locked funds were not exposed to the same bug, asked exchanges to blacklist the attacker's address, and invited the attacker to make contact for a bug bounty payment. Its total value locked fell from about $147 million to $127 million according to DefiLlama. No return of funds is documented in the sources consulted.
Sources
- HalbornSecondary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
- CryptoNews.net (syndicating Cointelegraph reporting of Team Finance's statement)Secondary · retrieved 2026-08-01
- CryptoNews.net (syndicating Cointelegraph)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Team Finance hack — October 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/team-financehttps://itokenly.com/hacks/team-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.