Gamma Strategies Loses $4.5 Million as Flash Loan Exploits a Misconfigured Price Threshold
Gamma Strategies, an Arbitrum-based concentrated liquidity management protocol, lost at least $4.5 million to an exploit on January 4, 2024.
The exploit transaction landed on-chain at approximately 03:30 UTC, and security researchers flagged unusual activity almost immediately. Early reports initially pointed to CryptoAlgebra as the affected protocol before the victim was correctly identified as Gamma. Gamma itself acknowledged the breach roughly ninety minutes after the attack began.

A follow-up statement confirmed deposits had been frozen across all public vaults as a containment measure:
All public vaults/hypervisors have had deposits shut down. You may withdraw your funds if need be. Our vaults will continue to be managed normally for now, but deposits are currently shut down until we identify and mitigate the problem.
The incident followed closely behind the Orbit Bridge hack, which had cost that project more than $80 million just days earlier at New Year. That piece had posed the question of whether the industry could "do better this year" — a question this exploit answered almost immediately, and not favorably.
Credit for tracking the incident goes to Gamma Strategies, Charles Wang, and PeckShield.
01The Mechanism
Gamma published a thread laying out the preliminary root cause, with a full post-mortem still to come. Separately, Paladin's Charles Wang outlined a comparable attack vector that could apply to similar protocols.
The exploit used flash loans to distort the valuation of deposits, letting the attacker mint a disproportionately large number of LP tokens. Gamma's vaults had four separate deposit-protection measures in place, but the attack still succeeded because certain vaults permitted an unusually wide range of price movement before those protections would trigger. Because the flaw is tied specifically to the deposit process, Gamma left deposits paused across its vaults while investigating further.
Gamma explained the root cause directly:
The main issue is with the settings we placed on (2) the price change threshold.
It was placed too high allowing for up 50-200% price change on certain LST and stablecoin vaults. This allowed the attacker to manipulate the price up to the price change threshold and mint a disproportionately high number of LP tokens.
PeckShield subsequently published a diagram tracing the full attack flow.
02Following the Funds
The attacker's address — 0x5351536145610aa448a8bf85ba97c71caf31909c, active on both Ethereum and Arbitrum — had been funded via Tornado Cash two and a half hours before the attack started. Part of the exploit ran through attack contract 0x4b57adc00ac38f74506d29fc4080e3dc65b78a69, with one representative transaction recorded at 0x025cf285….
Most of the stolen assets were bridged back to the attacker's Ethereum address, where the USDT portion was converted into roughly 1,535 ETH (about $3.4 million). Around $1.1 million in DAI and gDAI remained on Arbitrum, and the total loss to Gamma may ultimately prove higher than the initial figure.
The team reached out to the attacker on-chain, a gesture that typically signals hope for a whitehat return of funds. However, roughly 1,000 ETH had already been deposited into Tornado Cash, making a voluntary return look unlikely.
03Collateral Damage
The initial mislabeling cost Crypto Algebra reputational standing before the correction was made. Several unrelated protocols paused their own contracts out of caution while the situation was unclear, and DEXs Camelot and Quickswap both moved to clarify publicly that the issue did not originate in their own code.

Separately, BlockSec identified a series of smaller-scale attacks against Dyson Money, a protocol with a similar design.
04A Repeat Offender
Gamma Strategies previously operated under the name Visor Finance, and the project carries a rocky history predating the rebrand. In June 2021, Visor suffered a $500,000 loss through a privileged function, which the team characterized at the time as "not a rug". That November, another hack was downplayed as "economic arbitrage."
Then, in December 2021, an infinite-mint bug drained $8.2 million — a loss severe enough that the rebrand to Gamma Strategies, along with a token migration, was announced just two days later.
Since that rebrand, Gamma has reportedly had no further incidents, and it has been said that no original developers or founders remain involved with the project. The protocol has undergone three audits — from Consensys Diligence and Arbitrary Execution, both in March 2022, and from Certik in July 2021 — though because this exploit stemmed from how individual vaults' price-change tolerances were configured rather than a flaw in the underlying code, it likely fell outside the scope of those reviews.
The exploit adds to what has been a steady stream of hacks heading into 2024, a pace that, if a new bull run materializes, could end up dwarfing the losses of the previous cycle.
Get new scam files the moment we publish them — usually 2–3 emails a week.