Unizen Loses $2.1M as Attackers Exploit a Post-Upgrade Contract Flaw
Unizen, an Ethereum-based DEX, lost $2.1 million on March 8th to a wave of attacks that struck shortly after the protocol pushed an upgrade to its DEX aggregation contract.
Security firm Cyvers flagged the activity as it was unfolding that day; Unizen itself didn't confirm the breach until roughly seven hours later. Because the attacks unfolded over several hours, some users initially assumed the DEX was simply offline for the upgrade, only learning about the exploit after the fact. RevokeCash advised users to check whether their wallets were exposed and to pull back token approvals using its revocation tool.

Upgradeable smart contracts have repeatedly proven to be a weak point across DeFi — recent incidents at Socket, as well as last year's Safemoon and Level Finance exploits, all trace back to the same pattern of contract upgrades opening the door to attackers.
According to writeups from Cyvers, SunWeb3Sec, Martin Granstrom, Blocksec, Chain Aegis, and Blockfence, multiple attackers exploited an unverified external call vulnerability that surfaced right after Unizen upgraded its DEX aggregation contract.
The upgrade itself was intended simply to cut ETH gas costs, but it inadvertently weakened the contract's security in the process. Users who had previously approved elevated spending limits for particular tokens ended up exposed: attackers drained those approvals, totaling more than $2.1 million in stolen funds.
The addresses and transactions identified in the incident include:
- Attacker 1 / Attack Contract 1: 0xb660cae1a59336676ea1887b15eb3c0badb90d78, with an attack transaction at 0xc12a4155c2c90707138e4aef8883c8f724371145823e2f661f19b93e5b3a9d6e.
- Attacker 2: 0xc596523b77ceb9567279B572c653ECF4BA763CB7, using Attack Contract 2 at 0x90a7482dD7fA28865f440EC0c3B783775AC01266; this actor carried out 14 attack transactions in total.
- Attack Address 3: 0xd440b92739f86b00d1135b5eea871751433da2d7, operating against Attacked Contract 3 at 0x2f744f784000de0b8f1a7da3f0021ad56c09ce1a, with an attack transaction at 0x30fef86a72ea7e1109ffeae572439995c78561ffeb968dcbd61c609efc60fdd9.
- Attacker 4: 0x4e2ce48f0b5d97bfd4be3f6c7b6479db1aa5b365, responsible for 13 attack transactions.
The full flow of stolen funds has been traced, and the proceeds ultimately landed in this address.
Compounding the confusion, Unizen's X feed was quickly flooded with phishing spam tagging the project's account, which buried legitimate updates about the hack — something Unizen addressed shortly afterward.
Unizen formally addressed its community about seven hours after the attack began, and its CTO later elaborated, describing the root cause as a minor bug in the gas-optimization upgrade that carried outsized consequences.
Two days after the exploit, Unizen posted a series of on-chain messages addressed to a "Security Professional," offering a 20% bounty for the return of the stolen funds. Those messages were sent via the following transactions:
- 0x13f8220624f61cfb002489821eeba9df392150285147c1aaf816f283ae7cc43e
- 0x351906b2406282042c7396ea960b7a52d305658097e3f25bae79be4cdbb7c311
- 0x015b7fd22c027abb9c237a4ecb3862b7c3f2acb857fe93175e4a6c8265d38857
- 0x0dc8ce3e98d006cd1ba446544b289d960477347e8826efa788d6b879a59cd09d
- 0xcbdba5e11d3becfe80f8fd710d04fd068ad722289869459a7ce4f1e7123e5946
- 0xdcfed8e883eec7f913c452b2ed0da29f3504722479400053482cddd7797f883f
- 0xd5d684f3f61de25bd04b8434bb9af23658377350dee16ed2575d377426cebd89
A few hours after that, Unizen announced it would reimburse any losses under $750,000 using USDC or USDT, with CEO and founder Sean Noga personally lending funds to the protocol to cover the shortfall. The same announcement included a walkthrough video showing users how to revoke spending-limit approvals on the platform.

Later that day, the CTO said the team had gathered sufficient evidence to move forward with a post-mortem, noting that a patch had already been applied to the gas-optimization contract and pledging heavier investment in security review for future upgrades regardless of prior risk assessments.
The saga wasn't quite over: on March 11th, Blockfence observed that one of the attackers appeared to be moving on to a new on-chain maneuver, depositing 128 ETH of the stolen funds into a Uniswap liquidity pool paired with the Yoink token. The attacker also left an on-chain message claiming that profits from their "highly profitable trading strategies" would be reinvested into Yoink.
Unizen's DEX aggregator had previously been audited by Halborn and Verichain back in 2022, but no audit documentation could be found covering the specific upgrade that led to this exploit.
Taken together, the incident is yet another case of an unverified external call vulnerability surfacing in an upgradeable contract — a pattern that thorough testing and auditing could plausibly have caught before it was exploited. Unizen's initial communication lagged behind the attack itself, but its subsequent handling — committing to reimbursement and engaging openly with its community — drew a notably positive response, with users on Unizen's Telegram and X channels expressing appreciation as the reimbursement process got underway.
Get new scam files the moment we publish them — usually 2–3 emails a week.