Unizen (2024) — Crypto Hack
LaunderedUnizen's DEX aggregation logic was exploited for ~$2.1M through a vulnerability in the protocol's internal exchange routing.
Summary
Unizen's DEX aggregation logic was exploited for ~$2.1M through a vulnerability in the protocol's internal exchange routing.
How It Was Compromised — DeFi via Smart Contract Exploit
On March 5, 2024, Unizen, an ecosystem aggregator and DEX, was exploited for approximately $2.1M. The attacker identified a vulnerability in the protocol's internal exchange routing logic that allowed them to manipulate token prices and extract value from the protocol's liquidity pools. The exploit was executed through a series of transactions that bypassed the protocol's intended security checks. Unizen's CEO later confirmed the exploit and announced a compensation plan for affected users.
Fund Flow & Laundering Analysis
Stolen tokens were immediately swapped to ETH via decentralized exchanges. The ETH was then moved through multiple intermediary wallets before being deposited into Tornado Cash. Unizen offered a 10% bounty for the return of the funds and engaged blockchain analytics firms to track the stolen assets.