Unizen hack — March 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 9, 2024 |
| Target type | Decentralised exchange |
| Loss | $2,100,000Published estimates range $2,100,000 to $2,180,000Price at time of incident |
| Method | Access control flawA gas-optimisation upgrade to the proxy behind Unizen's DEX-aggregation contract on Ethereum introduced an external call whose target was not adequately validated. An attacker could make the contract call arbitrary addresses and, through them, execute transfers against any wallet still holding an open token approval to the contract. |
| Chains | Ethereum |
| Audited beforehand | Halborn and Verichains audited earlier Unizen contracts in 2022; per Halborn's and Vidma's analyses the March 2024 gas-optimisation upgrade that introduced the flaw was not re-audited before deployment. |
| Outcome | Users reimbursed |
What happened
On 9 March 2024 an attacker drained roughly $2.1 million from users of Unizen, a cross-chain trade aggregator, by abusing token approvals held against its Ethereum aggregation contract.
The money did not come from a protocol treasury. Unizen had recently upgraded the proxy behind its aggregation contract, a change reviewers describe as intended to optimise gas usage. The upgraded code performed an external call without adequately restricting the call target, so an attacker could direct the contract to call arbitrary addresses and, through them, move tokens out of any wallet that still had an open approval to it. Halborn described the root cause as an unsafe external call. A forensic review of the transactions found the attack executed across fourteen transactions through two attack contracts, sweeping many victim wallets at once. PeckShield publicly flagged an approve issue and Cyvers detected the transactions on-chain.
The proceeds were taken in USDT and converted to DAI. Roughly five months later 2,179,859 DAI was moved to a fresh wallet, swapped for about 865 ETH on Uniswap, and passed through Tornado Cash in 26 transactions. Unizen offered the attacker a 20% bounty; the attacker never engaged.
Founder and CEO Sean Noga loaned the company funds to reimburse users personally. Anyone who lost $750,000 or less was made whole in USDC or USDT sent directly to the affected wallet, beginning 11 March; larger losses were handled case by case.
The headline figure is consistently reported as about $2.1 million at the time of the incident. The upper bound of the range reflects the 2,179,859 DAI later traced and laundered, a face value recorded roughly five months afterwards rather than a valuation at the moment of the theft.
Law enforcement
Unizen said it engaged law enforcement and forensic investigators and offered the attacker a 20% bounty. No arrests or seizures have been reported.
Sources
- Cointelegraph (syndicated via TradingView)Secondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Dapp ExpertSecondary · retrieved 2026-08-01
- VidmaSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Unizen hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/unizenhttps://itokenly.com/hacks/unizenPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.