Unverified Router Addresses Cost Dexible $2M — Then Its PR Response Made Things Worse
Dexible, the decentralized exchange aggregator, lost a combined $2 million on Ethereum and Arbitrum on a Friday. Contracts were paused quickly once the issue was spotted, but the team's official announcement didn't go out until more than nine hours after the exploit — and over five hours after Peckshield had already flagged the activity publicly.
According to Dexible's own thread, its tech lead "discovered the attack early on", but the "Twitter channel was not able to respond in time" — even as several unrelated promotional tweets went out during that same window.

01A tone-deaf response
When Dexible eventually addressed the incident, part of its messaging landed poorly:
There's no excuse for an exploit, but these things happen
After being pushed on this, the team pointed toward rekt.news's own leaderboard as justification, adding simply:
exploits happen in DeFi.
Credit: Dexible, Peckshield, Beosin
02The vulnerability
Dexible's newly released v2 contracts let users specify their own trade routing through a selfSwap function. As the team's post-mortem (circulated as a PDF via Telegram and Discord) put it:
embedded in each request to swap was a "route" of what DEX to call and what data to send to that DEX to execute a swap
The flaw was that this routing information was never checked against anything — there was no on-chain allowlist confirming the destination was actually a DEX contract:
the router address was not verified on-chain in any way. This meant that instead of calling a DEX smart contract, the hacker simply called a token contract with a request to "transferFrom" any account that had spend approval on the Dexible contract
03Addresses and losses
Attacker addresses (identical across Ethereum, Arbitrum, and BSC): 0x684083f312ac50f538cc4b634d85a2feafaab77a
Example transaction: 0x138daa4cbeaa3db42eefcec26e234fc2c89a4aa17d6b1870fc460b2856fd11a6
Only a small number of accounts were impacted overall, with the bulk of the loss reportedly traced to a single address tied to BlockTower Capital, which lost 18 million TRU tokens — worth roughly $1.4 million at the time, according to CoinDesk.
Altogether, about $1.5 million was drained on Ethereum and funneled to Tornado Cash. An additional $450,000 was lost on Arbitrum, bridged over to BSC, and then similarly laundered through Tornado Cash.

04The audit question
Dexible's post-mortem also tried to explain why unaudited code had been shipped, leaning on the team's track record:
A formal audit was not performed on the latest set of contracts. We had several community members and Dexible engineers review the code, and they did not find the vulnerability. The core engineer that created the contracts has over 25 years of software engineering experience, and he did not see the vulnerability. Upon reviewing one of the hacker's transactions, however, he immediately understood how it was executed.
An audit isn't a guarantee of safety, but it clearly would have helped here. Even seasoned engineers can miss flaws in their own code, particularly when the focus during development is on shipping features for users rather than adversarial review. Security nonetheless has to come first in this space — plenty of unaudited protocols have already found their way onto the leaderboard as a result of skipping that step.
As Dexible itself summed it up:
exploits happen in DeFi.
Get new scam files the moment we publish them — usually 2–3 emails a week.