Approval Exploit Drains $6.4M From Seneca Protocol Users
Seneca Protocol users lost roughly $6.4 million on February 28 in an exploit that abused token approvals across Ethereum and Arbitrum. The incident was first flagged publicly by spreekaway on X.
Within a day, around 80% of the stolen funds had been sent back. The remaining portion ended up split across two addresses, which may indicate a bounty arrangement with the attacker.

Notably, a security researcher had already identified the same underlying bug during Seneca's audit contest in November 2023 — a contest the team later canceled.
Seneca had described its codebase as "battle-tested" and pointed to its public GitHub repository in a post-incident statement on X. That claim came just after the project had abruptly shut down its Sherlock-hosted audit contest, citing code-licensing concerns.
The team then launched weeks later, citing a completed audit from Halborn Security as justification. According to Seneca, the Chamber contract — the source of the eventual bug — had been reviewed as part of that audit. Halborn's report did flag some approval-related issues, but not the specific flaw that was exploited.
Less than two months after launch, the vulnerability was found and exploited. Separately, several community members reported being removed from Seneca's Discord after raising concerns about the bug.
Users who interacted with the protocol are advised to revoke any outstanding token approvals. The affected token contracts are listed below.
Ethereum:
PT-ezETH: 0x529eBB6D157dFE5AE2AA7199a6f9E0e9830E6Dc1
apxETH: 0xD837321Fc7fabA9af2f37EFFA08d4973A9BaCe34
PT-weETH: 0xBC83F2711D0749D7454e4A9D53d8594DF0377c05
PT-rsETH: 0x65c210c59B43EB68112b7a4f75C8393C36491F06
Arbitrum:
PT-weETH: 0x11446bbb511e4ea8B0622CB7d1437C23C2f3489b
stEUR: 0x7C160FfE3741a28e754E018DCcBD25dB04B313AC
PT-aUSDC: 0x4D7b1A1900b74ea4b843a5747740F483152cbA5C
wstETH: 0x2d99E1116E73110B88C468189aa6AF8Bb4675ec9
PT-rsETH: 0x2216E32006BB80d20f7906b88876964F9AF68aFb
Credit for reporting and analysis: Crypto Smith, Seneca, Spreek, Beosin Alert.
How the exploit worked: The attacker exploited a flaw in Seneca's code to pull assets from wallets that still held active approvals to Seneca's contracts. By crafting specific calldata, the attacker called transferFrom to move tokens that users had approved for the protocol directly to their own address — effectively draining any liquid staking tokens sitting undeployed in victims' wallets.
Compounding the problem, Seneca's contracts could not be paused during the attack because of a flawed implementation of the pause mechanism: the pause and unpause functions were marked internal, meaning there was no external way to invoke them.
Even Seneca's own team was affected — 50,000 senUSD was drained from the team's address, an amount that had been approved 33 days earlier but never actually deployed.
In total, more than 1,900 ETH was stolen, with various LSTs swapped into ETH and held across three addresses:
Exploiter address 1: 0x94641c01a4937f2c8ef930580cf396142a2942dc
Exploiter address 2: 0x5217c6923a4efc5bcf53d9a30ec4b0089f080ed0
Exploiter address 3: 0xe83b072433f025ef06b73e0caa3095133e7c5bd0
Example attack transaction: 0x9f371267

Seneca publicly acknowledged the exploit a few hours later and urged users to revoke approvals, though by then the funds were already gone.
Some hours after that, Seneca sent an on-chain message, also posted on X, offering the attacker a 20% bounty in exchange for returning the funds as a whitehat.
The attacker subsequently returned 1,537 ETH to a Gnosis Safe address and moved 300 ETH to two new addresses:
Address 1: 0x0C77350C4BDe539FfCee261A149dbc6e6afDA517
Address 2: 0xa07c64E55F52AAf5c361321CF01b316eCbddB5A9
Seneca said a post-mortem would follow once the full investigation was complete.
On-chain records show the exploiter's address was funded five months prior via FixedFloat and sat dormant until shortly before the attack. The full fund flow can be traced here.
Multiple members of the Web3 security community, including one researcher, had raised concerns before the exploit occurred. A Seneca team member also drew criticism for a since-deleted tweet that touted the project's code quality while disparaging Sherlock, the audit platform Seneca had walked away from. The project also publicly denied any legal liability for the incident, and had continued marketing itself even as these warnings circulated.
Because the attacker returned most of the funds, the worst-case outcome was largely avoided — but the episode underscores the value of extensive, independent security review before and after launch.
Get new scam files the moment we publish them — usually 2–3 emails a week.