T
iTokenly

UwU Lend (second exploit) hack — June 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 13, 2024
Target typeLending protocol
Loss$3,700,000Published estimates range $3,500,000 to $3,720,000Price at time of incident
MethodContract logic errorAfter the 10 June oracle attack the protocol was patched and unpaused, but according to CertiK it continued to treat the uUSDE collateral the attacker had minted during that first incident as legitimate. Holding roughly 60 million sUSDe of that collateral, the same attacker borrowed against it and drained the uDAI, uWETH, uLUSD, uFRAX, uCRVUSD and uUSDT pools. CertiK's account frames this as reuse of stale collateral rather than a repeat of the flash-loan oracle manipulation used three days earlier; Beosin and BlockSec, cited by The Block, characterised the second incident as a flash loan exploit consistent with the first. The mechanism is therefore contested between named firms.
ChainsEthereum
OutcomeUsers reimbursed

What happened

UwU Lend, an Ethereum lending protocol, was drained a second time on 13 June 2024, three days after a larger attack on 10 June. Cyvers Alerts flagged the transactions as they occurred; SlowMist, CertiK, Beosin and BlockSec published analyses.

Analysts disagree on whether the second attack repeated the first. On 10 June the attacker used flash loans to distort the sUSDe and USDe price feeds and took roughly $19.3 million to $20 million. UwU Lend then said it had identified and resolved the flaw, which it described as unique to the sUSDe market oracle, unpaused the protocol and began repaying bad debt. According to CertiK, the protocol continued to treat the uUSDE collateral the attacker had minted during the first incident as legitimate: the attacker 'had gained a significant number of uUSDE tokens from the first exploit and was still holding them,' which 'allowed the threat actors to exploit the remaining uUSDE amounts and drain all other UwULend pools.' Unchained reports the attacker used 60 million sUSDe from the previous hack as collateral. The uDAI, uWETH, uLUSD, uFRAX, uCRVUSD and uUSDT pools were drained and the proceeds converted to ether. The Block, citing Beosin and BlockSec, instead described the second incident as a flash loan exploit consistent with the first, attributed to the same perpetrator.

The size is reported inconsistently. Cyvers, The Block and Unchained give about $3.7 million; SlowMist's figure, cited by The Defiant, is $3.72 million; Crypto Briefing, working from CertiK's account, gives $3.5 million. Combined losses across the two June incidents are generally stated as about $23 million.

UwU Lend's founder Michael Patryn, known onchain as 0xSifu, offered the attacker a 20% bounty in exchange for returning 80% of the stolen funds, then a $5 million bounty to the first person to identify and locate them. Neither produced a return. The protocol repaid depositors from its own funds, disclosing $9.7 million of bad debt repaid as of the second attack; no source establishes that reimbursement was completed.

Sources

  1. The BlockSecondary · retrieved 2026-08-01
  2. Crypto Briefing (citing CertiK)Secondary · retrieved 2026-08-01
  3. UnchainedSecondary · retrieved 2026-08-01
  4. The Defiant (citing SlowMist)Secondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "UwU Lend (second exploit) hack — June 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/uwu-lend-second-exploit
https://itokenly.com/hacks/uwu-lend-second-exploit

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.