Inside SushiSwap's Overnight Scramble to Contain a $15,000 Sushibar Exploit
Just as SushiSwap appeared to be regaining its footing, an overnight exploit tested its new leadership.
Pseudonymous developer 0xMaki took over lead development of SushiSwap after founder Chef Nomi was found to have let greed get the better of him and cashed out. When DeFi Summer ended and the original food-themed farming craze faded, many assumed the protocol was finished. Its developers, however, kept building regardless, and SushiSwap re-emerged with an expanded product lineup. The relaunch, though, has not been entirely smooth.

Late one night, an unknown actor found a hole in SushiSwap's smart contracts and extracted roughly $15,000 before the team of developers managed to shut the exploit down. rekt spoke with 0xMaki about how the incident unfolded.
0xMaki explained that, following Nansen's earlier report on the protocol, he had personally been monitoring the Sushibar to keep arbitrage opportunities in check. He'd noticed a handful of small, odd transactions beforehand but hadn't suspected anything serious since the bar continued to function normally. The first minor transactions had appeared two to three days earlier, but activity escalated to an automated, high-volume pace on the day the issue came to a head.
The first public flag came via Discord, where a user named Monstar asked 0xMaki about unusual activity in the Sushibar, noting that stakers weren't receiving their expected Sushi rewards, and linked three suspicious transactions (one, two, three). 0xMaki initially replied that everything was functioning as intended and that the amounts involved looked negligible, possibly even a losing trade for whoever was behind it.
Monstar pushed back, pointing out that the claimable balance in the bar had dropped noticeably, and that the transactions appeared to let users claim the underlying LP tokens directly rather than converting them into Sushi as designed — meaning stakers weren't being paid at all. 0xMaki wondered aloud if the front-end tool known as "Boring App" was simply misbehaving, but Monstar clarified that someone had apparently found a way to route around Boring App entirely, withholding Sushi from everyone else in the pool, and shared a further transaction along with the wallet address behind the claims.
0xMaki confirmed the team was working on a fix, said no user funds were directly at risk, and described it as an exploit targeting the Sushibar's accrued fees — an expensive but useful bug report, given that the bar would forgo roughly $10,000 in fees for the day.
Asked for his first reaction, 0xMaki said his initial instinct was disbelief that the bar itself could be compromised — he suspected a front-end issue rather than a contract flaw, since the transactions didn't immediately add up. But when the bar's balance failed to grow the way it should have, he realized within about fifteen minutes that something was genuinely wrong and reached out to fellow developer Banteg. Banteg was unable to help: it was 6 a.m. his time and he was occupied with the Pickle/Cornichon project, and with the rest of the Sushi development team asleep across European and Tokyo time zones, 0xMaki — the only one based in North America — was initially left to handle the situation alone.
He eventually brought in Andy, a strategist at yEarn and former MakerDAO smart-contract engineer, along with Daniel Que, a former Coinbase employee. Reproducing and diagnosing the issue took the team three to four hours in total. Ultimately only about $15,000 was lost, since the Sushibar accrues just $20,000-$30,000 in fees on a typical day — of which 0.05% flows to liquidity pools through a manual process that itself carries a risk of failed transactions.
Asked whether it amounted to a hack or an exploit, 0xMaki was unequivocal: a genuine exploit, executed skillfully, and one the perpetrator deserved to profit from — adding that he believed he had since worked out who was responsible. He said he was more impressed than embarrassed by the episode, framing this kind of unexpected vulnerability as something that ultimately strengthens the ecosystem, even where audits are already rigorous. Only about $15,000 was lost to this particular actor, though 0xMaki noted there could have been others behaving similarly and that it warranted a closer look — this instance stood out mainly because it began affecting the entire Sushibar.
Recounting the timeline, 0xMaki said that around 11:28 p.m. his time, he and Andy began working on a fix. While reviewing the smaller transactions to confirm they were harmless, it became clear they were not. Andy, freshly off a flight and jet-lagged, had to leave to sleep, briefly leaving 0xMaki on his own — until security researcher samczsun got involved, after 0xMaki reached out for lack of any other available smart-contract security specialist. Even samczsun, however, had prior plans for a Saturday night and couldn't stay engaged, leaving 0xMaki without backup once again. He tried Chef Nomi and the rest of the core developers, posting a step-by-step account of the situation in the main team channel in the hope someone would wake up. He then remembered Daniel Que, who had been keeping the project accountable from early on, called him, and briefed him on the situation. (0xMaki noted that he no longer has contact with Chef Nomi.)

By 2:35 a.m., the team had reproduced the exploit and understood its mechanics well enough to start building a patch; by 3:19 a.m., the fix was ready. While the rest of the team woke up and continued refining the patch, 0xMaki turned his attention to identifying the attacker, discovering that the wallet mainly held SNX and ETH. Reviewing its transaction history convinced him this wasn't a wallet created specifically to carry out an attack, but rather belonged to someone who had stumbled onto the vulnerability while exploring the protocol. His reasoning: the wallet had received numerous tips in SNX and ESD tokens, suggesting its owner was active in both communities, likely via Discord. By cross-referencing senders and recipients of tips across multiple dates — with help from a contact inside the SNX community — 0xMaki was able to narrow down a likely identity.
With the whole team awake, a preliminary fix was deployed and the exploit stopped. Word of the incident subsequently reached Twitter.
In an editorial aside, rekt noted receiving what it described as "indisputable evidence" from the suspect: an image captioned "could never be me."
0xMaki emphasized that no user actually lost funds, since the drained amount represented profit that would otherwise have gone to xSushi holders. The team planned to cover the shortfall by distributing $15,000 worth of Sushi from the treasury back to stakers on a pro-rata basis. Asked for a final message to the attacker, 0xMaki invited them to get in touch directly, noting the protocol has other contracts worth testing and that the team pays bug bounties. He also thanked everyone involved in the episode — including the attacker.
Get new scam files the moment we publish them — usually 2–3 emails a week.