Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.5718
24h: -1.60%
Trade UDS
Gate.io
Gate.io
UDS / USDT
KuCoin
KuCoin
UDS / USDT
MEXC
MEXC
UDS / USDT
BingX
BingX
UDS / USDT
BitMart
BitMart
UDS / USDT
LBank
LBank
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
WEEX
WEEX
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT
Pionex
Pionex
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Sushiswap v3
Sushiswap v3
UDS / USDT
Picol
Picol
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

INFLUENCER LEVEL

Based on the number of subscribers

MULTIPLIER

up to 10k

x1.1

10-25k

x1.25

25-100k

x1.5

100k-250k

x2

250k-1m

x3

1m+

x5

Post links to Undeads Forum messages or Undeads products to receive additional rewards

Post limits and staking coefficients applied similar to Forum posts

Discord, Telegram, Twiter

Post in Forum to earn rewards!

UDS Rewards
  1. Home
  2. Crypto-Detective
  3. Scallop Loses 150,000 SUI in Exploit Targeting Deprecated Rewards Contract

Scallop Loses 150,000 SUI in Exploit Targeting Deprecated Rewards Contract

Scheduled Pinned Locked Moved Crypto-Detective
2 Posts 2 Posters 20 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • bonkB Offline
    bonkB Offline
    bonk
    wrote last edited by
    #1

    b03ff8c7-9b3e-48b5-99e1-7e1d275ff629-image.png

    Scallop, a money market protocol on the Sui Network, was drained of approximately 150,000 SUI on Sunday after an attacker exploited a deprecated rewards contract tied to the protocol's sSUI spool — the incentive layer for SUI depositors. The team detected the incident and froze the affected contract within minutes of the attack, disclosed publicly at 12:50 UTC on April 26. Core lending and borrowing pools were never touched, user deposits across every other Scallop market remained safe, and the freeze on core contracts was lifted just under two hours later at 14:42 UTC. Scallop confirmed it will cover 100% of the loss from its treasury without diluting user yields.
    The exploit traced back to a deprecated V2 spool package that Scallop had published in November 2023 — more than 17 months before the attack. On Sui, deployed packages are immutable, meaning old versions remain callable unless developers explicitly implement version-gating to block access. The attacker identified an uninitialized last_index counter in the stale code, which tracks accumulated rewards for stakers, and staked roughly 136,000 sSUI to exploit it. The math treated the position as if it had existed since the spool launched in August 2023, allowing the attacker to harvest approximately 162 trillion reward points that redeemed one-to-one for 150,000 SUI from the rewards pool. A full post-mortem and audit of remaining legacy packages is expected to follow.

    1 Reply Last reply
    0
    • chainsniffC Offline
      chainsniffC Offline
      chainsniff
      wrote last edited by
      #2

      frozen in minutes, fixed in two hours, treasury covering 100% of losses. Scallop's crisis comms team was ready. the security team less so.

      1 Reply Last reply
      0


      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups