Flash Loan Attack Drains $11M From Saddle Finance's sUSD Metapool
Saddle Finance suffered an $11 million exploit on April 30, 2022, though roughly $3.8 million of that total was recovered by security firm BlockSec before the attacker could move it. The incident pushed the Curve-derived protocol to #43 on rekt.news's leaderboard, a sharp jump from its debut appearance in January of the prior year.

Saddle initially stated that user funds were safe, then clarified that the claim applied only to the funds that hadn't already been stolen — leaving the $11 million taken firmly in the "not safe" category.
Analysis from SlowMist and PeckShield traced the root cause to the protocol's sUSDv2 metapool, which pairs Synthetix's sUSD against saddleUSD-V2 LP tokens representing a DAI/USDC/USDT pool. The vulnerability stemmed from an older version of the MetaSwapUtils library that calculated LP token value during metapool swaps without referencing a VirtualPrice — a flaw already patched in a newer version of the contract, but one the live swap logic was still routing through.
Using flash loans, the attacker executed a series of sUSD/saddleUSD-V2 swaps within the metapool to distort the LP token's price, then swapped back to extract a larger amount of sUSD than they had put in.
The exploiter's wallet was initially funded through Tornado Cash (address 0x63341b…). The main attack transaction moved 3,375 ETH (tx 0x2b023d…), followed by a second transaction worth 557 ETH (tx 0xe7e047…). BlockSec's whitehat counter-transaction recovered 1,357 ETH (tx 0x9549c0…). At the time of reporting, some funds had started moving through Tornado Cash again, but most remained sitting in the attacker's wallet.
This was not a new class of bug for Saddle. In November 2021, the team had already published a writeup on this exact vulnerability after Synapse Protocol — which used Saddle-derived code — narrowly avoided losing $8.2 million to the same issue. BSC-based nerve.fi was hit by an identical attack vector around the same time. Saddle's fix to the MetaSwapUtils library merged that December, but the patched logic was evidently never wired into the actual metapool swap path, leaving the exact same weakness exploitable more than four months later.

Get new scam files the moment we publish them — usually 2–3 emails a week.