Consensus 2025
00:15:11:02
Share this article

Sushi DEX Approval Contract Exploited for $3.3M

Developers asked users to revoke contracts as a security measure early Sunday.

(DALL-E/CoinDesk)
(DALL-E/CoinDesk)

A smart contract on decentralized-finance protocol Sushi's exchange services was exploited early Sunday, developers said in a tweet.

The exploit specifically involves the "RouterProcessor2" contract, which is used to route trades on the SushiSwap exchange.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

"It seems the SushiSwap RouterProcessor2 contact has an approve-related bug, which leads to the loss of >$3.3M loss," security firm PeckShield flagged during Asian morning hours on Sunday. Sushi developers later confirmed the exploit.

According to several tweets from multiple security firms, the $3.3 million apparently came from a single user, @0xsifu, a popular pseudonymous trader in Crypto Twitter circles.

DefiLlama developer @0xngmi, who is also pseudonymous, said Sunday that the exploit seemed to affect only users who approved SushiSwap contracts in the past four days.

Meanwhile, SushiSwap head developer Jared Grey asked users to revoke permissions for all contracts on SushiSwap as a security measure, adding the team was "working with security teams to mitigate the issue."

Shaurya Malwa

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.

Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.

He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa