MonoX Loses Over $31 Million After Attacker Manipulates Its Own MONO Token Price
MonoX, a DEX that had only launched the previous month on both Polygon and Ethereum, lost more than $31 million across the two chains after an attacker manipulated the price of its own native token, MONO, and used it to drain the protocol's pools.
Unlike conventional AMMs that pair two deposited assets in a single pool, MonoX uses a Single Token Liquidity design: each deposited token is paired against the protocol's internal virtual stablecoin, vCASH, rather than against another real asset. The project had marketed this structure as enabling more efficient swap routing — a feature that, in this case, gave the attacker an equally efficient path to convert an artificially inflated token balance into other assets sitting in the pools.

Two coordinated strikes, minutes apart
The protocol was hit by two attacks in rapid succession, using the same underlying method. The Polygon deployment was drained of roughly $19.4 million first; seventeen minutes later, the identical technique was applied against the Ethereum deployment, extracting a further $12 million.
MonoX addressed the incident with a statement posted to its Telegram announcements channel, later mirrored on Twitter:
...A method in the swap contract was exploited and boosted MONO token price to sky high. The attacker then used $MONO to purchase all the other assets in the pool...
...We also really wish to have a chance in talking with the "attacker". We value very much for what we've built for the current and future MonoX, and most importantly our users and their funds; PLEASE reach out to us!
(Credit for early analysis of the exploit goes to @BlockSecTeam.)
How the price manipulation worked
The vulnerability sat in the swapTokenForExactToken function of the Monoswap contract, deployed on both Polygon and Ethereum, and it involved MONO, the token MonoX had recently launched.
A separate internal function, _updateTokenInfo, was responsible for updating token prices after each swap through the pools — but it placed no restriction on using the same asset as both the tokenIn and the tokenOut in a single transaction. By repeatedly swapping MONO for itself in this way, the attacker set up a loop in which the recorded price of tokenOut overwrote the price of tokenIn on every pass, ratcheting MONO's internal valuation upward with each additional swap. Once the token's price had been pushed far above its real value, the attacker exchanged the now-overvalued MONO for nearly every other asset held across MonoX's Single Token Liquidity pools.
Both Halborn and PeckShield had previously audited the Monoswap contract, leaving open the question of how a flaw this straightforward escaped two separate reviews.
Assets drained
The total haul, broken down by asset, came to:
- 5.7M MATIC ($10.5M)
- 3.9k WETH ($18.2M)
- 36.1 WBTC ($2M)
- 1.2k LINK ($31k)
- 3.1k GHST ($9.1k)
- 5.1M DUCK ($257k)
- 4.1k MIM ($4.1k)
- 274 IMX ($2k)

Exploit transactions: Polygon, Ethereum.
Exploit contracts: Polygon, Ethereum.
Destination of stolen funds (roughly $31.4M combined): Polygon address holding about $19.4M, and Ethereum address holding about $12M.
A young protocol, a familiar lesson
The exploit wiped out over $30 million from a protocol that wasn't yet a month old — one that had actually surpassed $30M in total value locked just three days before the attack. It's another reminder that DeFi's ability to attract capital quickly still isn't matched by the maturity of its security practices. Incidents like this one add to a growing body of lessons for the industry, even as new, unproven protocols keep launching — and some of them, inevitably, keep failing in the same ways.
Get new scam files the moment we publish them — usually 2–3 emails a week.