Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.5931
24h: -0.14%
Trade UDS
Gate.io
Gate.io
UDS / USDT
KuCoin
KuCoin
UDS / USDT
MEXC
MEXC
UDS / USDT
BingX
BingX
UDS / USDT
BitMart
BitMart
UDS / USDT
LBank
LBank
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
WEEX
WEEX
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT
Pionex
Pionex
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Sushiswap v3
Sushiswap v3
UDS / USDT
Picol
Picol
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

INFLUENCER LEVEL

Based on the number of subscribers

MULTIPLIER

up to 10k

x1.1

10-25k

x1.25

25-100k

x1.5

100k-250k

x2

250k-1m

x3

1m+

x5

Post links to Undeads Forum messages or Undeads products to receive additional rewards

Post limits and staking coefficients applied similar to Forum posts

Discord, Telegram, Twiter

Post in Forum to earn rewards!

UDS Rewards
  1. Home
  2. FAQ
  3. Is Scallop Safe? What the April 2026 Exploit Revealed About DeFi Security

Is Scallop Safe? What the April 2026 Exploit Revealed About DeFi Security

Scheduled Pinned Locked Moved FAQ
2 Posts 2 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • johnblockbusterJ Offline
    johnblockbusterJ Offline
    johnblockbuster
    wrote last edited by
    #1

    9d2749f1-96cb-4073-a556-2fef54d50f35-image.png

    Q: Was Scallop hacked and what actually happened?
    On April 26, 2026, Scallop suffered an exploit that drained approximately 150,000 SUI — worth around $40 million — from a deprecated rewards contract tied to its sSUI spool incentive layer. The attacker exploited a stale V2 spool package that Scallop had deployed in November 2023, more than 17 months before the attack. The vulnerability centered on an uninitialized last_index counter that tracks accumulated rewards for stakers. By staking roughly 136,000 sSUI, the attacker manipulated the math to treat their position as if it had existed since the spool launched in August 2023, harvesting approximately 162 trillion reward points that redeemed for 150,000 SUI from the rewards pool.

    Q: Were user funds at risk and how did Scallop respond?
    Core lending and borrowing pools were never touched during the exploit — the attack targeted a peripheral deprecated contract, not the main protocol infrastructure. The Scallop team detected the incident quickly, froze the affected contract within minutes, and restored full protocol operations within under two hours. Most importantly, Scallop confirmed it would cover 100% of the loss from its own treasury without diluting user yields or affecting depositor balances in any way. The rapid response and commitment to full reimbursement were widely noted as a best-practice example of incident management in DeFi.
    Q: What does this mean for the security of Scallop going forward?
    The exploit highlighted a specific risk inherent to Sui's architecture: deployed packages are immutable, meaning old code versions remain callable on-chain indefinitely unless developers explicitly implement version-gating to block access. Scallop is expected to publish a full post-mortem and conduct a comprehensive audit of every remaining legacy package to identify and close similar vulnerabilities. The incident has also prompted broader discussion across the Sui DeFi ecosystem about how builders should manage immutable code and deprecated contracts over time — a challenge that will only grow as protocols accumulate more deployed packages with age.

    1 Reply Last reply
    0
    • madmaxM Offline
      madmaxM Offline
      madmax
      wrote last edited by
      #2

      Sui's Move-based parallel execution giving lower fees than Ethereum is a genuine structural advantage, but "hasn't been tested across multiple full market cycles" is the honest caveat that belongs on every Sui DeFi investment thesis.

      1 Reply Last reply
      0


      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups