ChainBleedv0.1 · open intel
← back to feed·REENTRANCY2021-09-03 · 4y ago
Incident · SLOWMIST

OpenZeppelin

Contract Vulnerability
Estimated loss
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
REENTRANCY
REENTRANCYBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

OpenZeppelin released a bug fix analysis. Whitehat Zb3 submitted a serious reentrant vulnerability in OpenZeppelin's TimelockController contract on August 21, 2021, which affected a project hosted on the Immunefi vulnerability bounty platform. The project chose to remain anonymous and has paid an undisclosed amount (including an anonymous bonus) to White Hat. OpenZeppelin paid White Hat a bonus of $25,000 to recognize their contribution to community security and released a patch. As far as it knows, this is the only serious vulnerability that OpenZeppelin has in its open source smart contract library. The vulnerability has been patched in the affected projects, and OpenZeppelin has released an updated contract version to fix the vulnerability. All projects that use TimelockController should be migrated. Attack method (per SlowMist): Contract Vulnerability. Reported loss: -.

Primary source
https://forum.openzeppelin.com/t/timelockcontroller-vulnerability-post-mortem/14958
Sourced from
slowmist
Technical record
chain
protocol
OpenZeppelin
bug_class
reentrancy
date_occurred
2021-09-03
loss_usd
source_id
sm:openzeppelin::2021-09-03
Related — same bug class· reentrancy
2026-04-28
1mo ago
ETH
BCB
Reentrancy — classic call-before-state-update
reentrancy
$39.8K
UNRATED
2026-03-06
3mo ago
BITCOI
Solv Protocol
Reentrancy Attack
reentrancy
$2.70M
UNRATED
2026-01-15
4mo ago
ARB
Futureswap (reentrancy)
Reentrancy during liquidity provision → excess LP mint → 3-day cooldown wait → burn for redemption
reentrancy
$74.0K
AUDIT-CATCHABLE
2026-01-14
4mo ago
ARB
FutureSwap
Reentrancy Attack
reentrancy
$74.0K
UNRATED
2025-07-15
11mo ago
BASE
Arcadia V2
Rebalancer contract reentrancy hack
reentrancy
$2.50M
UNRATED
2025-07-09
11mo ago
GMX
Contract Vulnerability
reentrancy
$42.00M
UNRATED
ChainBleed — live web3 threat intelligence