ChainBleedv0.1 · open intel
← back to feed·ORACLE2020-11-30 · 5y ago
Incident · SLOWMIST

SushiSwap

Price Manipulation
Estimated loss
$15.0K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
ORACLE
ORACLEBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2021-01/Sushi_Badger_Digg_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

The liquidity mining project SushiSwap (SUSHI) community governor 0xMaki announced in the Discord group that the SushiSwap vulnerability has been fixed, and the lost funds (approximately US$10,000) will be compensated from the SUSHI asset library. Previously, SushiSwap was attacked by a liquidity provider. The attacker obtained between 10,000 and 15,000 US dollars in a transaction. However, after this operation was discovered by 0xMaki, 0xMaki sent a transaction to the attacker with a message saying "I found you and we are working hard to fix it. Contact me on Discord to get bug bounty-0xMaki". According to analysis, the attacker uses SLP and WETH to create a new token pool, uses SLP1 of the new token pool to convert in Sushi Maker, and uses a small amount of SLP to transfer all SLPs in the Sushi Maker contract to the tokens they created. In the pool, all the handling fees of the corresponding transaction pair within a period of time will be collected into the bag. Repeat this process for other trading pairs and continue to make profits. Attack method (per SlowMist): Price Manipulation. Reported loss: $ 15,000.

Primary source
https://www.btcfans.com/en-us/flash/id-43549
Sourced from
slowmist
Technical record
chain
protocol
SushiSwap
bug_class
oracle
date_occurred
2020-11-30
loss_usd
$15,000
source_id
sm:sushiswap::2020-11-30
Related — same bug class· oracle
2026-05-03
1mo ago
BSC
TUB
BSC token contract exploit (vector undisclosed)
oracle
$27.7K
UNRATED
2026-05-01
1mo ago
ARB
Sharwa.Finance
Oracle Price Manipulation
oracle
$32.9K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Price Manipulation
oracle
$228.0K
UNRATED
2026-04-27
1mo ago
BASE
Singularity Finance
Oracle Misconfiguration Exploit
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Contract Vulnerability
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Exploit
oracle
$413.0K
UNRATED
ChainBleed — live web3 threat intelligence