Visor Finance hack — December 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | December 21, 2021 |
| Target type | Other |
| Loss | $8,100,000Published estimates range $8,100,000 to $8,200,000Price at time of incident |
| Method | Access control flawThe RewardsHypervisor deposit function accepted an arbitrary contract address from the caller and called owner() and delegatedTransferERC20() on it. An attacker contract implementing that interface satisfied the check without moving any real tokens while still being credited with vVISR receipts, and re-entered deposit during the external call to double the receipts minted. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
On 21 December 2021 an attacker drained 8,812,958 VISR tokens from the staking contract of Visor Finance, an Ethereum protocol that managed automated liquidity positions on Uniswap v3. Reporting at the time put the value between roughly $8.1 million and $8.2 million, based on a VISR price near $0.93 immediately before the attack.
The vulnerable RewardsHypervisor deposit function accepted an arbitrary contract address supplied by the caller and then invoked owner() and delegatedTransferERC20() on it. An attacker contract that implemented the expected interface could therefore satisfy the check without transferring any real tokens, while the staking contract still credited it with vVISR receipt tokens. Independent analysis of the transaction found the attacker also re-entered the deposit function during that external call, causing the contract to issue two batches of 97,624,975 receipts each, 195,249,950 vVISR in total, which were then redeemed for VISR.
VISR fell from about $0.93 to roughly $0.04 within hours, a drop of more than 95%. The stolen tokens were not recovered.
Two days later the project announced it was merging with Gamma Strategies. A GAMMA token was minted and distributed at a 1:1 ratio to holders of VISR, vVISR and tVISR recorded in a snapshot taken on 21 December before the exploit, so holders were made whole in the new token rather than the drained one. The team said the replacement hypervisor contracts were slated to be audited by Quantstamp and ConsenSys Diligence by the end of January 2022. Because the loss is denominated in a token whose price collapsed on the news, the published figures differ slightly and neither $8.1 million nor $8.2 million is more authoritative than the other.
Sources
- Crypto BriefingSecondary · retrieved 2026-08-01
- CryptoSlateSecondary · retrieved 2026-08-01
- Optimaginating (independent security analysis)Secondary · retrieved 2026-08-01
- Gamma StrategiesPrimary · retrieved 2026-08-01
Official post-mortem: https://gammastrategies.medium.com/visor-merges-with-gamma-a-re-org-focusing-on-security-and-performance-b4deaf67e273
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Visor Finance hack — December 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/visor-financehttps://itokenly.com/hacks/visor-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.