T
iTokenly

WOOFi Swap hack — March 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 5, 2024
Target typeDecentralised exchange
Loss$8,750,000Published estimates range $8,600,000 to $8,750,000Price at time of incident
MethodOracle or price manipulationFlash-loan-driven manipulation of WOOFi's synthetic proactive market making (sPMM) pricing algorithm on Arbitrum. The Chainlink fallback price check that was meant to reject extreme deviations did not cover the WOO token, so the manipulated internal price was never validated.
ChainsArbitrum
OutcomeUnresolved

What happened

On 5 March 2024 at 15:49 UTC an attacker drained WOOFi Swap's WOO liquidity on Arbitrum by manipulating the protocol's synthetic proactive market making (sPMM) pricing algorithm.

According to WOOFi's own post-mortem, the attacker used flash loans to assemble roughly 7.7 million WOO tokens and sold them into WOOFi. The sPMM algorithm responded by repricing WOO at an extreme value close to zero, reported as about $0.00000009, after which the attacker swapped roughly 10 million WOO back out at near-zero cost. The sequence was repeated three times inside a very short period. Cyfrin's independent analysis found the oracle configured for WOO was returned as the zero address, so the Chainlink fallback check that should have rejected the deviation never executed; Cyfrin also notes the attack depended on WOO's low liquidity. Halborn reached the same conclusion about the Chainlink fallback not covering WOO, and adds that the same functionality had been in operation since 2021 without incident, becoming exploitable only after WOOFi expanded to a WOO lending market on Arbitrum.

WOOFi's monitoring system flagged the swaps and the swap contracts were paused at 16:02 UTC, with Hypernative, Chainalysis, Wintermute and SEAL911 assisting. The team offered the attacker a 10% white-hat bounty, posted a separate bounty on Arkham Intelligence for identifying information, and said WOOFi Pro, Stake and Earn were unaffected.

The figure is contested and the two numbers measure different things. WOOFi's post-mortem, The Block and Halborn put the attacker's net profit after flash-loan repayment at about $8.75 million, which is the value recorded here. Cyfrin describes the sPMM algorithm as having been exploited for $8.6 million, while also referring to $8.75 million in profits. As of the sources reviewed, all of which date from March 2024, no return of funds, arrest or user compensation plan had been reported; the position after that date was not verified for this entry.

Sources

  1. WOO X / WOOFiPrimary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. CyfrinSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://woox.io/blog/en/woofi-spmm-exploit-post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "WOOFi Swap hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/woofi-swap
https://itokenly.com/hacks/woofi-swap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.