Scam Alert: This is How $300k in ETH Was Stolen From Uniswap, a DeFi DApp

An exploit at UniSwap, a DeFi dapp, saw imBTC, a wrapped BTC created by imtoken and Tokelon, loss $300k in Ethereum (ETH).
Published by
Scam Alert: This is How $300k in ETH Was Stolen From Uniswap, a DeFi DApp

An exploit on a liquidity pool in Uniswap, a DeFi, resulted in the loss of slightly over $300,000 in Ethereum (ETH).

The loss of $300,000 in ETH, an appreciating asset, is a big dent—and in the face of sophisticated hackers who understand the ins and outs of the protocol, more work needs to be done on the leaky DeFi roof.

Advertisement

What is Uniswap?

Uniswap is a decentralized protocol built on the Ethereum blockchain that facilitates the exchange of Ethereum and tokens via liquidity pools.

Instead of an order book, of which there have been claims of manipulation, the protocol leverages liquidity pool where participants earn money for supplying any amount of funds for liquidity.

Anyone can create a liquidity pool, which is a market, by providing an equal amount of ETH and ERC-20 token, and providing his ideal exchange rate.

Total Value Locked in USD
Advertisement

Advertisement

The imBTC Pool exploited

However, today’s exploit was different. Hackers targeted imBTC, a wrapped version of Bitcoin created by imtoken in partnership with Tokelon, a decentralized exchange, available at UniSwap.

The DEX acknowledged the attacked and notified the community that the funds on the imBTC liquidity pool was drained after the hacker utilized an attack vector on tokens derived from the ERC-777 standard on UniSwap.

Good news is that BTC held in custody wasn’t affected but imBTC transfers have been temporarily paused as the DEX evaluates the situation.

What is the ERC 77 Standard?

Like ERC 20, the ERC 777 is a standard.

Both co-exist in the Ethereum blockchain but the tokens bear different feature serving different needs. The standard is advanced by Jordi Baylina, Jacques Dafflon, and Thomas Shababi.

It seeks to improve some inefficiencies of the ERC-20 standard, popular because of its simplicity but underperforms because of its underpowered.

Still, it is backward compatible with ERC 20 tokens and adds “hooks” which are payable functions for tokens.

There are no payable functions in ERC-20 tokens meaning if one wants to exchange ETH for DAI, for instance, one must initiate a transaction to approve an infinite amount of DAI and another transaction to swap it for ETH.

This is because in the ERC-20 standard, code will only execute when they receive ETH, and not tokens.

Attackers took advantage of Hooks and stole $300,000 in ETH

Because of “hooks” enabled in the ERC 777 standard, there is no need of double transactions easing the free flow of funds between different dapps.

But it exposes dapps to re-entry attacks. Re-Entry attacks are not new as it was an exploit the DAO attacker used. This time round, the same exploit is possible with ERC 777 tokens.

And the attacker used it to steal $300,000 worth of ETH because before this attack, Uniswap V1 didn’t support but after the last upgrade to V2, it introduced ERC 777 support. It just didn’t take time for the attack to figure out the vulnerability and take advantage of it.

Advertisement
Share
Dalmas Ngetich

Dalmas is a very active cryptocurrency content creator and highly regarded technical analyst. He’s passionate about blockchain technology and the futuristic potential of cryptocurrencies and enjoys the opportunity to help educate bitcoin enthusiasts through his writing insights and coin price chart analysis. Follow him at @dalmas_ngetich

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • News

$7B Virtu Financial Holds $63M XRP as Whales Accelerate Daily Sell-Off

Virtu Financial, a $7 billion Wall Street firm, has revealed $63 million in XRP holdings.…

November 1, 2025
  • News

Breaking: Coinbase Nears $2B Deal to Buy Stablecoin Platform BVNK

Coinbase is reportedly closing in on a $2 billion acquisition of stablecoin infrastructure startup BVNK.…

November 1, 2025
  • News

Coinbase CLO Fires Back at Senator Murphy Over ‘Corruption Factory’ Claim

Coinbase’s Chief Legal Officer, Paul Grewal, has publicly criticized U.S. Senator Chris Murphy. The lawmaker…

November 1, 2025
  • News

Crypto Prices Rise: Why Are BTC, ETH, LTC, XRP, SHIB, and ADA Up Today?

Major crypto prices saw solid gains after a week of downturns. Bitcoin, Ethereum, Litecoin, XRP,…

November 1, 2025
  • News

Michael Saylor’s Strategy Eyes S&P 500 Spot Amid Bitcoin-Backed Credit Products Launch

Michael Saylor’s Strategy is setting its sights on the S&P 500 as it pushes forward…

October 31, 2025
  • News

Bitcoin White Paper Turns 17 Today as Satoshi’s $120B Fortune Climbs $2.8 Billion

Seventeen years ago today, Satoshi Nakamoto emailed a nine-page document that changed the world. It…

October 31, 2025