Forgotten SushiMaker Bridge Let a Bot Skim 81 ETH From DIGG Fees
A single trade converting 0.001 of an asset into 81.68 ETH first looked like a serious breach of SushiSwap. Closer inspection showed something narrower: a known DeFi wallet had exploited a configuration gap involving Badger DAO's DIGG token, and the amount at risk had already been contained by the time it was noticed.
Mechanism of the incident

The root cause was a missing "bridge" setting inside SushiMaker, the contract responsible for converting 0.05% of trading fees into rewards for xSUSHI stakers. Normally, SushiMaker liquidates accumulated fees into ETH and then into SUSHI. When a new trading pair lacks direct ETH liquidity, a manually configured bridge routes the conversion through a different, adequately liquid asset instead.
When Sushiswap's Onsen program added new non-ETH pairs, no bridge was ever set up for the DIGG/WBTC pair. Without that bridge, SushiMaker tried to convert DIGG/WBTC fees directly against a thinly liquid DIGG/ETH pool, causing heavy slippage. That slippage effectively redirected the fee value to whoever supplied liquidity to the DIGG/ETH pool — rather than to xSUSHI holders, who should have received it.
Who benefited, and how
One address, already flagged as an active user of bots and flash loans, seeded liquidity in the DIGG/ETH pool and let SushiMaker's conversion attempt spill value into it. The transaction in question shows SushiMaker trying to process roughly 24 hours' worth of the 0.05% DIGG/WBTC swap fee through that shallow pool. Nansen data and follow-up review of the same wallet turned up a pattern of prior attempts to exploit the same gap:
- 0x90fb0c9976361f537330a5617a404045ffb3fef5972cf67b531386014eeae7a9
- 0x0af5a6d2d8b49f68dcfd4599a0e767450e76e08a5aeba9b3d534a604d308e60b
- 0xcec93808a657d00cbb0245711e9419d0ea278b3a60a9a6d0a8c3353523c0e982
- 0xe0527f7befaea54257113a09c8b3f4cd416e11a0e196cd2ba2e5e07c47767ddf
Scope of the damage
No liquidity-provider deposits or existing xSUSHI positions were touched. The loss was limited to one day's accumulated 0.05% DIGG/WBTC fee revenue — about 81 ETH — which went to the opportunistic liquidity provider instead of xSUSHI holders. A bridge for DIGG has since been added to the SushiMaker contract, closing this particular gap.
Why it happened

The fix for missing bridges existed for weeks before the incident but had to be applied by hand every time a new non-ETH pair launched. Because that manual step was skipped for DIGG/WBTC, the opening remained available to be found and used. According to discussion in the Sushiswap Discord, the team did not commit to automating the process going forward, opting instead to continue applying it manually for future pairs.
Broader takeaway
SushiSwap holds roughly $1.9B in TVL to defend, and this episode is a reminder that even routine configuration steps in the deployment pipeline can be exploited if left as manual, human-dependent processes. Protocols of this size are watched continuously by both sophisticated actors and casual observers — in this case, a Twitter user going by "simp2win" attempted to publicly analyze the exploiter's activity, though with limited accuracy. The wallet behind the trades also used Ethereum call data to respond directly, pushing back on inflated claims about the size of their profit.
Get new scam files the moment we publish them — usually 2–3 emails a week.