T
iTokenly

Wintermute (Optimism OP grant) hack — June 2022

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 9, 2022
Target typeOther
Loss$17,600,000Published estimates range $15,000,000 to $35,000,000Price at time of incident
Recovered$15,600,000
MethodAccess control flawCross-chain address collision. 20 million OP was sent on Optimism to a Gnosis Safe address Wintermute controlled only on Ethereum mainnet. The attacker replayed the pre-EIP-155 (chain-ID-less) Gnosis Safe proxy factory deployment transactions on Optimism to recreate the factory at the same address, then mass-created Safes until the deployer nonce reproduced Wintermute's exact address, deploying a Safe they owned at the address holding the tokens.
ChainsOptimism
OutcomePartially recovered

What happened

In May 2022 the Optimism Foundation lent market maker Wintermute 20 million OP tokens from its Partner Fund so Wintermute could provide liquidity when OP listed on centralised exchanges. Wintermute supplied a Gnosis Safe address it controlled on Ethereum mainnet but had never deployed on Optimism. The Foundation sent the tokens to that address on the layer-2 on 27 May 2022, where they sat at a contract that did not yet exist.

On 5 June 2022 an attacker took them. As Inspex documented, the Gnosis Safe proxy factory on Ethereum had originally been deployed in transactions predating EIP-155 and therefore carrying no chain ID, so the attacker replayed those transactions to recreate the factory at the identical address on Optimism. They then generated roughly ten thousand Safe contracts across dozens of transactions until the deployer's nonce produced Wintermute's exact address, and deployed a Safe they owned there.

Published valuations of the 20 million OP differ sharply because OP had only just begun trading and was falling fast. Crypto Briefing put the loss at about $17.6 million on the day, CoinDesk reported $15 million, and Decrypt described the tokens as worth $35 million at the time of the breach. The token quantity is not disputed.

The attacker converted 1 million OP to ether, sent 1 million OP to Vitalik Buterin's wallet with an on-chain message, and on 10 June returned 17 million OP, about $15.6 million at that day's price, keeping 2 million as a self-declared bounty. The Optimism Foundation said the 1 million OP sent to Buterin was also being recovered. Wintermute chief executive Evgeny Gaevoy accepted responsibility, calling it a serious error, and the firm undertook to make Optimism whole.

Sources

  1. InspexSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. Crypto BriefingSecondary · retrieved 2026-08-01
  4. DecryptSecondary · retrieved 2026-08-01
  5. CryptoSlateSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Wintermute (Optimism OP grant) hack — June 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/wintermute-optimism-op-grant
https://itokenly.com/hacks/wintermute-optimism-op-grant

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.