CryptoReal
CASE FILE — Jun 3, 2024

Fee-Multiplier Flaw Drains $6.8M From Velocore's Linea and zkSync Pools

Velocore, a decentralized exchange built for layer-2 networks, lost more than $6.8 million on June 2nd after an attacker exploited a weakness in its Balancer-style constant-product market maker contract, draining liquidity pools deployed on both Linea and zkSync.

The breach was serious enough that the Linea team temporarily froze block production on its network — a halt that has since been lifted. Velocore has since offered the attacker a 10% white-hat bounty in exchange for returning the funds, but as of publication the offer has gone unanswered.

Linea's decision to pause its sequencer during the incident has drawn scrutiny over how centralized the chain's operations still are. Velocore, for its part, had passed several security audits before the exploit occurred — a reminder that audits do not guarantee a contract is airtight.

01How the exploit unfolded

Blockchain investigator Officer CIA raised the first alarm after noticing irregular activity in Velocore's liquidity pools. Velocore's own post-incident report later confirmed that the attacker funded the operation through Tornado Cash, bridged the funds to carry out the attack, and routed the stolen assets back through Tornado Cash afterward.

The attack began when the exploiter called the contract's velocore__execute() function directly, using it to simulate oversized withdrawals that pushed the internal feeMultiplier value far higher than intended. That inflated multiplier drove the effectiveFee1e9 parameter above 100%, which the attacker then leveraged through a flash loan to pull most of the tokens out of the pool and compress its size.

A subsequent small, single-token withdrawal triggered an underflow bug that minted an outsized quantity of liquidity tokens. This let the attacker repay the flash loan with ease and walk away with roughly $6.8 million in ETH. Security firm Beosin's analysis attributed the root cause to a missing permission check on the LP pool: the attacker was able to call velocore__execute (function selector 0xec378808) on the LP contract directly, with parameters crafted specifically to distort feeMultiplier. Because that value determines how many tokens change hands in a swap, the manipulated figure was then fed into a second call — this time to the execute function (selector 0xd3115a8a) via the router contract — to siphon funds out of the pool.

02Addresses and transactions

Attacker address: 0x8cdc37ed79c5ef116b9dc2a53cb86acaca3716bf

Sums referenced in this case file

Contracts exploited:

Attack transaction 1: 0xed11d5b013bf3296b1507da38b7bcb97845dd037d33d3d1b0c5e763889cdbed1

Attack transaction 2: 0x37434e674efc4e7cfeed7746095301ace5636028906fe548b786ead286e35eb0

Attack transaction 3: 0x4156d73cadc18419220f5bcf10deb4d97a3d3f7533d63ba90daeabc5fd11ba17

Final destination of funds before Tornado Cash: 0xe4062fcade7ac0ed47ad794028967a2314ee02b3

03Linea's sequencer halt

Linea confirmed it froze its sequencer mid-attack specifically to stop additional funds from being bridged out, noting that it could not reach Velocore in time to coordinate a response. The network described the move on X as a last-resort measure taken to protect users.

Linea acknowledged that its long-term goal is to remove this kind of centralized intervention capability once the network achieves sufficient decentralization, but defended the decision in the moment. As it put it: "Most L2s, including Linea, still rely on centralized technical operations which can be leveraged to protect ecosystem participants. Linea's core value is a permissionless, censorship-resistant environment so it was not a decision we took lightly."

04Aftermath

Velocore has since opened negotiations with the attacker, dangling the 10% bounty — roughly $680,000 — as an incentive to return the remaining stolen ETH. Per its own documentation, Velocore says it had already completed three separate audit rounds, carried out by Zokyo, Hacken, and Scalebit back in August 2023, none of which caught this particular flaw.

Whether Velocore can recover the funds, and whether this proves to be an isolated incident or the start of a longer pattern of trouble, remains an open question for the protocol going forward.

Velocore
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.