Rogue Contractor Diverts $3.1M From Sushi's MISO Auction Platform
A contractor hired to build out the MISO auction for a project called "JayPegs Automart" swapped his own wallet address into the contract in place of the designated auctionWallet — a single substitution that redirected $3.1 million away from where it was supposed to go.
The incident raises an uncomfortable question for an industry that markets itself as trustless: how much of that trust still rests on the individuals writing the code.

01The public accusation
The response was swift and unusually aggressive. In a tweet later deleted, Sushi CTO Joseph DeLong named names, publicly identifying who he believed was behind the diverted funds:
The Miso front end has become the victim of a supply chain attack. An anonymous contractor by with the GH handle AristoK3 injected malicious code into the Miso front end. We have reason to believe this is @eratos1122.
The accused developer, eratos1122, pushed back publicly, but the Sushi team stood by their claim.
DeLong went further, compiling and publishing eratos1122's resume, personal website, Facebook profile, email address, and invoice records in a publicly accessible Google document. That document has since been made private, though its contents circulated for a period.
02The money came back — and then some
Within hours of the personal details being exposed, and amid threats from the Sushi team to bring in the FBI, the funds were returned: 865.094 ETH sent back against roughly 864.8 ETH originally taken, meaning slightly more came back than was actually stolen. Readers are left to draw their own conclusions about why.
03Funding trail
On-chain analysis traced the funding sources behind the address associated with the incident:
- Address believed to belong to the attacker: 0x3dDD8b6D092df917473680d6C41F80F708C45395
- That address was funded by: 0xe5f7ae14f02894fcf46ffcb225cc4db38f3c4962, which links to Binance
- Which was itself funded by: 0xba6f4f83329b9500672c6955fd5082c9434aaf74, tied to three separate Binance transactions (one, two, three)
- Which traces back to: 0x482c9f85644f1686c490d38291511657da767e61, an address previously linked to 0xAK, with connections to three FTX-related transactions (one, two, three)
04Reputation on the line

The episode is a reminder that developers who cross over from legitimate security work into exploitation don't always cover their tracks as well as they might think. Given how public and consequential the accusation was, DeLong and the Sushi team evidently had real confidence in their evidence — confidence that hasn't wavered even after the original tweets and documents disappeared.
Before this, eratos1122's GitHub reflected a solid track record and considerable development experience. Regardless of whether the accusation holds up, the incident is likely to follow him.
This marks yet another close call for SushiSwap, a protocol that has brushed up against disaster in rekt.news coverage before without a full-blown catastrophe resulting. Still, a refunded hack is a hack, and this one earns a spot on the leaderboard regardless of the outcome.
The timing overlapped with 0xMaki's departure from his leadership role at SushiSwap, which some observers used as an opening to take shots at the Uniswap rival — though it's worth weighing the incentives behind such commentary.
Get new scam files the moment we publish them — usually 2–3 emails a week.