CryptoReal
CASE FILE — Apr 10, 2023

A Fake Uniswap V3 Pool Let Attackers Pull $3.3M From SushiSwap's New Router

Over a single weekend, attackers extracted more than $3.3 million from SushiSwap users by exploiting a newly deployed routing contract.

Anyone who had granted an approval to Sushi's RouteProcessor2 contract — live for only four days before the incident — was exposed, and the exposure spanned 14 different chains.

Sushi's Head Chef, Jared Grey, confirmed the bug and urged users to revoke their approvals immediately. He later said the protocol was safe to use again once the vulnerable contract had been pulled, and promised a full post-mortem would follow.

Amid the scramble, 0xSifu — previously covered on rekt.news as DeFi's favourite villain — lost 1,800 ETH, while a wave of white-hat rescue activity played out in parallel. One user claimed to have gone after 0xSifu's funds specifically to whitehat them, though the attempt appears to have been mishandled: only 100 ETH was ultimately returned. BlockSec also stepped in, adding this to its recent run of whitehat recoveries.

Because the flawed contract had only existed for a few days, relatively few users had approved it — sparing SushiSwap what could otherwise have been a much larger, protocol-wide event. Even so, for a protocol already carrying plenty of reputational baggage, the timing was unfortunate.

How many more scandals can Sushi absorb?

01How the exploit worked

Technical credit goes to Inspex, 0xfoobar, and ernestognw.

The router's processRoute function did not adequately validate the arbitrary data it accepted. This let an attacker construct a fraudulent Uniswap V3 pool and substitute their own contract address in place of a genuine liquidity pool. When the router's uniswapV3SwapCallback function then executed, the attacker's contract was able to pull — or "yoink" — tokens out of any address that had approved RouteProcessor2.

Sums referenced in this case file

0xfoobar summarized the flaw as follows:

SushiSwap router exploit comes from a bad callback. Although the line 328 comment is correct, line 340 does not check the pool deployer. So you can impersonate a V3Pool, do a no-op swap, call safeTransferFrom on an arbitrary ERC20 and arbitrary from address on line 347

ernestognw.eth published a more detailed technical walkthrough.

Reference points: an example attack transaction, 0xea3480f1f1d1f0b32283f8f282ce16403fe22ede35c0b71a732193e56c5c45e8, and the vulnerable RouteProcessor2 contract on Ethereum at 0x044b75f554b886A065b9567891e45c79542d7357. A multi-chain list of addresses needing revocation was circulated for affected users.

02A protocol that keeps making headlines

Rather than posing any existential threat, this episode reads more like an embarrassment than a crisis. Losses weren't enormous, and exposure wasn't especially widespread; affected users were either drained or managed to revoke quickly, and white-hat intervention helped soften the PR fallout.

Sushi has rarely been free of controversy since it launched. It burst onto the scene during 2020's "DeFi summer," quickly establishing itself among the sector's marquee names alongside Uniswap, Curve, Aave, and Compound. A stretch of stagnation during the 2021 bull run gave way to internal infighting, and the arrival of a new head chef, Jared Grey, that October brought fresh scrutiny over his checkered history with a string of troubled projects.

Sushi arguably illustrates both the promise and the fragility of DAO-run organizations: a small, motivated team can reshape the DEX landscape within weeks, but once the initial momentum fades, a larger, more entrenched team can settle into complacency — or start treating the treasury as a personal resource.

Grey has since received an SEC subpoena, faced criticism over a thin bug-bounty program, and presided over sizable operating expenses — including a reported $500,000 tied to his own role.

The drama, it seems, is far from finished for Sushi.

SushiSwap
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.