T
iTokenly

Velocore hack — June 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 2, 2024
Target typeDecentralised exchange
Loss$6,800,000Published estimates range $6,800,000 to $7,600,000Price at time of incident
MethodContract logic errorMissing caller validation on the ConstantProductPool contract's velocore__execute() function let anyone invoke it directly with crafted parameters, including the feeMultiplier used in the pool's exchange arithmetic. A flash loan was used to obtain LP tokens and contract the pools, and the manipulated fee value was then carried into a call through the router contract so that a small withdrawal was treated as a far larger deposit, letting the attacker take out much more than had been deposited. Only volatile constant-product pools were affected; stable pools were not.
ChainsMultiple chains
Audited beforehandYes
OutcomeUnresolved

What happened

On 2 June 2024 an attacker drained the volatile constant-product liquidity pools of Velocore, a decentralised exchange deployed on the Linea and zkSync Era layer-2 networks. Velocore's post-mortem put the loss at roughly $6.8 million in ETH. The Block reported about $7 million, or around 1,700 ETH, and Merkle Science's tracing of the attacker's holdings put the figure nearer $7.6 million before conversion.

The bug was in the ConstantProductPool contract. Its velocore__execute() function did not verify that it was being called by the protocol's vault, so anyone could invoke it directly with crafted parameters. Each simulated withdrawal raised a feeMultiplier variable, and by repeating the call the attacker pushed the effective fee above 100 per cent. Because the fee arithmetic did not expect a value above 100 per cent, a subsequent small single-token withdrawal underflowed and minted an abnormally large quantity of LP tokens. Combined with a flash loan used to obtain LP tokens and contract the pools, that allowed the attacker to withdraw far more than was deposited. Stable pools were unaffected and Velocore said assets on Telos were secured.

Security firm Hexagate alerted Linea, whose operator halted block production between blocks 5,081,800 and 5,081,801 for about an hour to censor the attacker's addresses, a centralised intervention that drew criticism. Around 700 ETH had already been moved off Linea through a third-party bridge.

Velocore offered a 10 per cent white-hat bounty with a deadline of 3 June at 08:00 UTC. It went unanswered. Merkle Science reported that the proceeds were bridged to Ethereum via Across, consolidated into roughly 1,807 ETH and sent to Tornado Cash. Velocore said it had undergone multiple audits and committed to reimbursing affected users.

Sources

  1. UnchainedSecondary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. Merkle ScienceSecondary · retrieved 2026-08-01
  4. SolidityScanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Velocore hack — June 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/velocore
https://itokenly.com/hacks/velocore

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.