Thala (ThalaSwap) hack — November 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 15, 2024 |
| Target type | Decentralised exchange |
| Loss | $25,500,000Price at time of incident |
| Recovered | $25,160,000 |
| Method | Contract logic errorMissing bounds check in an unstake_max function added to Thala's v1 boosted farming contracts by a two-line patch deployed on 1 November 2024. The function did not verify that the amount a caller asked to withdraw was no larger than their actual staked balance, so the exploiter could pass an arbitrary value and receive liquidity provider tokens they had never staked. Affected pools were MOD/USDC, MOD/THL and THAPT/APT. Thala's post-mortem states the patch bypassed its normal security review because the change was judged too simple to need one. |
| Chains | Aptos |
| Outcome | Settled as bug bounty |
What happened
Thala is a decentralised finance protocol on the Aptos blockchain running an automated market maker, a liquidity staking product and the MOD stablecoin. On 15 November 2024, beginning at about 12:46 UTC, an exploiter withdrew liquidity provider tokens worth $25.5 million from Thala's v1 farming contracts.
The flaw lay in an unstake_max function introduced by a two-line patch to the boosted farming contracts on 1 November. The function never checked that the amount a caller requested was no more than the amount they had staked, so the exploiter could ask for an arbitrary quantity and receive LP tokens they had never deposited. The MOD/USDC, MOD/THL and THAPT/APT pools were affected. Thala's post-mortem says the patch skipped its normal security review because the change looked trivial.
Thala paused the affected contracts and froze roughly $11.5 million of the drained assets that were its own tokens, about $9 million of MOD and $2.5 million of THL, which limited what the exploiter could sell. Members of the SEAL 911 emergency response group, the security researcher known as Ogle, the audit firm OtterSec and law enforcement worked on identifying the exploiter. SEAL 911 member pcaversaccio said on-chain links made identification possible within minutes, after which the exploiter made contact and returned the funds without extended negotiation.
Everything was back with Thala by about 19:13 UTC the same day, roughly six and a half hours after the first exploit transaction, less $340,000 made up of a $300,000 protocol bounty and $40,000 in personal compensation to Thala's founders. The exploiter was never publicly named and no charges have been reported.
Law enforcement
Thala's post-mortem credits law enforcement with assisting in identifying the exploiter, alongside SEAL 911, the researcher known as Ogle, and OtterSec. No agency is named and no charges have been reported.
Sources
- Thala LabsPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Thala (ThalaSwap) hack — November 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/thalahttps://itokenly.com/hacks/thalaPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.