CryptoReal
CASE FILE — Oct 9, 2022

RSK's Flagship DeFi Protocol Loses $1.1M to a callTokensToSend Exploit

On October 4th, an attacker drained roughly $1.1 million from Sovryn, a DeFi protocol built on RSK, the Bitcoin-linked smart-contract sidechain that markets itself as one of the more secure smart contract networks available.

Sovryn's developers responded by switching affected contracts into "maintenance mode" to stop further losses, and disclosed the incident through a Twitter thread that read more like a victory lap than a postmortem. The move to pause contracts also sits awkwardly with Sovryn's positioning as a protocol built for a Bitcoin-native audience that tends to prize decentralization and censorship-resistance.

Genuinely Bitcoin-native DeFi remains largely aspirational, but strong marketing has never hurt fundraising: Sovryn's launch a year earlier was boosted heavily by Anthony Pompliano's promotion, which relied on an inaccurate claim that the protocol's TVL — nearly $2 billion at the time — exceeded that of Uniswap v3. That figure turned out to double-count native staked SOV, an error that prompted DeFiLlama to add a staking toggle to its TVL methodology and revise Sovryn's real figure down to about $52 million. Since then, TVL has fallen roughly 90% from its peak, and the SOV token is down about 99% from its all-time high a year prior.

Per Beosin's on-chain analysis, two legacy lending pools were hit: the RBTC pool (RSK-bridged Bitcoin), which lost 45 RBTC — worth roughly $900,000 — and the USDT pool, which lost 211,000 USDT. Beosin traced the root cause to the external call made by the callTokensToSend function.

Sums referenced in this case file

The attacker's wallet is identified as 0xc92ebecda030234c10e149beead6bba61197531a, with an example transaction documented on-chain.

Beosin's writeup lays out the mechanics step by step: the attacker first deployed the exploit contract and funded it with 0.03 RBTC, then used it to take out a flash loan of 8.20 RBTC spread across three pair addresses, depositing the full 8.23 RBTC borrowed. That liquidity position was then used to borrow 52,999 side tokens. Calling closeWithDeposit to repay the collateral, the attacker swapped 26,900 side tokens for 4.17 RBTC — but notably, only 26,000 of those side tokens had actually been minted into 22,653 Load Tokens, even though closeWithDeposit itself contains no minting logic. The attacker then routed the remaining side tokens through an external call from the attack contract into the protocol's mint function. Because the tokenPrice function calculates Load Token price using the current side-token count, and that count hadn't yet been updated at the time of the call, the mint produced more Load Tokens than it should have. The attacker then burned the 22,653 Load Tokens to redeem 27,086 side tokens, repeated the cycle in a loop to accumulate more side tokens, and finally converted everything back into RBTC. The proceeds were routed through Tornado Cash.

An update posted October 7th sought to reassure users, stating that roughly half of the stolen funds had already been recovered and that the Exchequer would fully cover any remaining user losses. Five days after the attack, a closing statement confirmed that all user funds stuck on the ETH bridge had been freed, with a single exception: users who had bridged in USDT to XUSD.

Bitcoin-adjacent DeFi has never lacked for entrants — bridged assets like WBTC and renBTC, and protocols such as Badger, all compete for this niche — but genuine Bitcoin participation in DeFi remains modest. Even WBTC, the largest such asset with roughly $5 billion in TVL, represents only a sliver of Bitcoin's $387 billion total market capitalization. Much of that gap comes down to trust: Bitcoin maximalists are broadly wary of wrapping their coins for use on other chains, and tend to view DeFi experimentation with suspicion relative to holding what they consider a purer form of money. An incident like this one is unlikely to change many minds on that point.

Sovryn
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.