CryptoReal
CASE FILE — Feb 20, 2023

Unverified Router Addresses Cost Dexible $2M — Then Its PR Response Made Things Worse

Dexible, the decentralized exchange aggregator, lost a combined $2 million on Ethereum and Arbitrum on a Friday. Contracts were paused quickly once the issue was spotted, but the team's official announcement didn't go out until more than nine hours after the exploit — and over five hours after Peckshield had already flagged the activity publicly.

According to Dexible's own thread, its tech lead "discovered the attack early on", but the "Twitter channel was not able to respond in time" — even as several unrelated promotional tweets went out during that same window.

01A tone-deaf response

When Dexible eventually addressed the incident, part of its messaging landed poorly:

There's no excuse for an exploit, but these things happen

After being pushed on this, the team pointed toward rekt.news's own leaderboard as justification, adding simply:

exploits happen in DeFi.

Credit: Dexible, Peckshield, Beosin

02The vulnerability

Dexible's newly released v2 contracts let users specify their own trade routing through a selfSwap function. As the team's post-mortem (circulated as a PDF via Telegram and Discord) put it:

embedded in each request to swap was a "route" of what DEX to call and what data to send to that DEX to execute a swap

Sums referenced in this case file

The flaw was that this routing information was never checked against anything — there was no on-chain allowlist confirming the destination was actually a DEX contract:

the router address was not verified on-chain in any way. This meant that instead of calling a DEX smart contract, the hacker simply called a token contract with a request to "transferFrom" any account that had spend approval on the Dexible contract

03Addresses and losses

Attacker addresses (identical across Ethereum, Arbitrum, and BSC): 0x684083f312ac50f538cc4b634d85a2feafaab77a

Example transaction: 0x138daa4cbeaa3db42eefcec26e234fc2c89a4aa17d6b1870fc460b2856fd11a6

Only a small number of accounts were impacted overall, with the bulk of the loss reportedly traced to a single address tied to BlockTower Capital, which lost 18 million TRU tokens — worth roughly $1.4 million at the time, according to CoinDesk.

Altogether, about $1.5 million was drained on Ethereum and funneled to Tornado Cash. An additional $450,000 was lost on Arbitrum, bridged over to BSC, and then similarly laundered through Tornado Cash.

04The audit question

Dexible's post-mortem also tried to explain why unaudited code had been shipped, leaning on the team's track record:

A formal audit was not performed on the latest set of contracts. We had several community members and Dexible engineers review the code, and they did not find the vulnerability. The core engineer that created the contracts has over 25 years of software engineering experience, and he did not see the vulnerability. Upon reviewing one of the hacker's transactions, however, he immediately understood how it was executed.

An audit isn't a guarantee of safety, but it clearly would have helped here. Even seasoned engineers can miss flaws in their own code, particularly when the focus during development is on shipping features for users rather than adversarial review. Security nonetheless has to come first in this space — plenty of unaudited protocols have already found their way onto the leaderboard as a result of skipping that step.

As Dexible itself summed it up:

exploits happen in DeFi.

Dexible
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.