> ## Content Index
> Fetch the complete content index at: https://www.metatalks.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# SushiSwap Exploited Due to a Bug in Smart Contract – Overview and User Guidelines
- URL: https://www.metatalks.ai/sushiswap-exploited-due-to-a-bug-in-smart-contract-overview-and-user-guidelines/
- Published: 2023-04-10T19:22:50.000Z
- Updated: 2023-04-10T19:22:50.000Z
- Author: Katelyn Chow
- Tags: sushiswap, #helen, exploit, hack

[SushiSwap](https://twitter.com/SushiSwap?ref=metatalks.ai), a decentralized finance (DeFi) protocol, [was exploited](https://decrypt.co/125799/sushiswap-smart-contract-bug-exploited-in-3-3-million-theft?ref=metatalks.ai) due to a bug in a smart contract. Users who traded in the past five days may be affected.

> Seems [@SushiSwap](https://twitter.com/SushiSwap?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai) was hacked. 🟥  
>  
> Fear not 🟩  
>  
> Follow this steps to revoke any contract you might have Interacted and forgotten.[https://t.co/SIzdAZk7ZV](https://t.co/SIzdAZk7ZV?ref=metatalks.ai)
> 
> — Fortizo (@TKatugwa) [April 9, 2023](https://twitter.com/TKatugwa/status/1644952706459529216?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

On April 9th, reports surfaced about the bug in a SushiSwap feature, which had caused the loss of millions of dollars. [Jared Gray](https://twitter.com/jaredgrey?ref=metatalks.ai), the CEO of SushiSwap, later confirmed an exploit and provided details ([thread](https://twitter.com/jaredgrey/status/1644914375151550464?ref=metatalks.ai)) on the actions undertaken to address the issue.

The main victim of the exploit, caused by the "approve-related bug" in SushiSwap's RouterProcessor2 contract, became a prominent member of the Crypto Twitter community known as [Sifu](https://twitter.com/0xSifu?ref=metatalks.ai), from whose wallet was stolen about 1,800 ETH, [according](https://twitter.com/peckshield/status/1644907207530774530?ref=metatalks.ai) to the crypto analytics firm [PeckShield](https://twitter.com/peckshield?ref=metatalks.ai).

![](https://lh5.googleusercontent.com/1gYCmUmyfhHDX5H0Z45n-2ftOYNFPK0gEkYlL70rjroeGzbrKAmlyw09UwR8XfduUj2YA4_g03TtilprS9yaNC45CJ4hV4i9kAHvWL4oKF8373fhhkbHIruF7nJiV8N6Emkt3vAaT6nvlY0n4zDZUVM)

After a separate investigation, [Ancilia](https://twitter.com/AnciliaInc?ref=metatalks.ai), a cybersecurity firm backed by Binance, concluded that the vulnerability resulted from a failure to validate access permissions during a swap transaction. The firm also discovered [a vulnerable contract](https://twitter.com/AnciliaInc/status/1644932592700129280?ref=metatalks.ai) on the Polygon network.

![](https://lh4.googleusercontent.com/C3r9FRio6kRrWULulEEg3R3UfLRcBavFZ9rexJgvUz72BR3LvqPr9fLexomoGMHECBQYLG7HK49Wenyo4-u-ZmAZVmTQBP-zfkHZihOjQ09G91yiknbhAylgU6QYLHH32ENdrT29iKyXqz2NM9uKP-A)

[PeckShield](https://twitter.com/peckshield?ref=metatalks.ai) and SushiSwap Head Chef Jared Grey [recommended](https://twitter.com/jaredgrey/status/1644925766696677376?ref=metatalks.ai) revoking the RouterProcessor2 contract on all chains. Here's a detailed [tutorial (thread)](https://twitter.com/lookonchain/status/1645044637818834944?ref=metatalks.ai) on that from the [@lookonchain](https://twitter.com/lookonchain?ref=metatalks.ai). And [here](https://slingshot.mirror.xyz/8OEm3pJ5vLcPrE8W3IBqfnq-IUGMhKBB368NZtCwz1I?ref=metatalks.ai), you can find a similar [tutorial for Polygon](https://slingshot.mirror.xyz/8OEm3pJ5vLcPrE8W3IBqfnq-IUGMhKBB368NZtCwz1I?ref=metatalks.ai).

[According to Ancilia, Inc.](https://twitter.com/AnciliaInc/status/1644929849218469888?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai), the technical root cause "is because in the internal swap() function, it will call swapUniV3() to set variable "lastCalledPool" which is at storage slot 0x00." They also added that "later on in the swap3callback function, the permission check gets bypassed."

In other words, by approving the bad contract, users inadvertently authorize the exploiter to take their tokens through the "yoink" function due to a bug in the "approve" mechanism of the SushiSwap router contract.

"The bug allows an unauthorized entity to essentially "yoink" tokens without the proper approval from the token owner," [explains](https://www.theblock.co/post/225473/sushiswap-hack?ref=metatalks.ai) The Block Research Analyst Brad Kay, adding: "Following the first attack for 100 ETH —[ possibly a white hat](https://twitter.com/trust%5F%5F90/status/1644895249058131971?s=20&ref=metatalks.ai) — it seems like another hacker came along and[ stole](https://twitter.com/trust%5F%5F90/status/1644900643608358913?s=20&ref=metatalks.ai) another 1800-ish ETH using the same contract but instead named their function "notyoink." ([Source](https://www.theblock.co/post/225473/sushiswap-hack?ref=metatalks.ai))

![](https://lh5.googleusercontent.com/Smxh8fAgWSRj8d1xMbPulwxpBf5-a8DQ3vOnlJadrwg4COsli5_gMMFRD9zR-c1wdi1wXnLgv---hkw7cQXKTuss43UIcxO7XquyF5lf8i_KIUIfY4eOGsHvusdfXxoNUESp_6n6weD32fLCE5Lypko)

> It seems the exploited RouteProcess02 contract has been deployed in multiple chains. [@SushiSwap](https://twitter.com/SushiSwap?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)  
>  
> Please \*REVOKE\* the following addresses ASAP.  
>  
> ETH: 0x044b7..7357  
> BSC: 0xd75f...6550  
> POLYGON: 0x5097...649a  
> AVAX: 0xbace...9c4f  
> FTM: 0x3e60...c715 [https://t.co/nWcI9oydW6](https://t.co/nWcI9oydW6?ref=metatalks.ai) [pic.twitter.com/1RVj2TP5C2](https://t.co/1RVj2TP5C2?ref=metatalks.ai)
> 
> — PeckShield Inc. (@peckshield) [April 9, 2023](https://twitter.com/peckshield/status/1644925384709009413?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

Early reports already [claimed](https://twitter.com/0xngmi/status/1644927715923963904?ref=metatalks.ai) that the number of SushiSwap users at risk was not too big:

> only users impacted by sushiswap hack should be those that swapped on sushiswap in the last 4 days, if you did so revert approvals asap or move your funds in affected wallet to a new wallet
> 
> — 0xngmi (llamazip arc) (@0xngmi) [April 9, 2023](https://twitter.com/0xngmi/status/1644927715923963904?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

The DeFi Llama team also published[ a list of contracts](https://gist.github.com/0xngmi/40c530a6dc219e62939ed911b5d5ac70?ref=metatalks.ai) across all chains that should be revoked across all chains and built [a tool](https://0xngmi.github.io/sushi-test-hack/?ref=metatalks.ai) to[ ](https://0xngmi.github.io/sushi-test-hack/?ref=metatalks.ai)check if any of your addresses have been affected.

According to Block Research Analyst Kevin Peng, the problematic contract has been approved by 190 Ethereum addresses thus far. On [Arbitrum](https://www.metatalks.ai/arbitrums-first-governance-proposal-caused-controversy-and-concerns-over-the-decentralized-nature-of-the-project/), however, over 2000 addresses have approved the bad contract.

> 🚨 Urgent update regarding Sushiswap's hack   
> All of you are at critical risk of having your wallet's crypto stolen. The only way to protect yourself is to update Sushiswap contracts here: [https://t.co/I0yhmom9iq](https://t.co/I0yhmom9iq?ref=metatalks.ai)  
> ⬆️ If you do not update, your wallet will 100% get hacked
> 
> — Sushi.com (@SushiSwapDev) [April 9, 2023](https://twitter.com/SushiSwapDev/status/1645147510602715136?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

Sunday morning, SushiSwap CTO [Matthew Lilley](https://twitter.com/MatthewLilley?ref=metatalks.ai) followed up with some additional details ([thread](https://twitter.com/MatthewLilley/status/1645116270726053890?ref=metatalks.ai)):

> If you have another address for where your funds went, then please contact us at security@sushi.com w/ the tx hash and chain you were on. We will continue to update everyone as we gather more information, and appreciate everyone working together with us to amend the situation.
> 
> — I'm Software 🦇🔊 (@MatthewLilley) [April 9, 2023](https://twitter.com/MatthewLilley/status/1645116410043981829?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

Jared Grey, on his turn, reported that more than 300 ETH of Sifu's stolen funds has since been recovered, with another 700 ETH in the process:

![](https://lh5.googleusercontent.com/czJBAmXk3jc2s1qwEbGsFrkIMpVJ3ioYyLQasQLEakaThSzNU37D1fXJ5hGCv2FXXFW0h8NEibG2khjSlLxsnnhtdhplcutTlOlBa_NVVdAgQ8DftbjvAidQAFVlcm4HdmXAzDzx8xkPzKQezh8_0ac)

The SushiSwap team has also [provided](https://twitter.com/SushiSwap/status/1645065346427277314?ref=metatalks.ai) a link that traders can use to check their accounts and revoke any permissions if necessary.

> 💡 To find out if you're vulnerable to the approval of RouteProcessor 2  
> 👉 Use this link to check and revoke if you have tokens approved.  
>  
> 🔓 [https://t.co/HUBz9Hi82h](https://t.co/HUBz9Hi82h?ref=metatalks.ai)
> 
> — Sushi.com (@SushiSwap) [April 9, 2023](https://twitter.com/SushiSwap/status/1645065346427277314?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

Later on, Sunday the SushiSwap team claimed the exchange is currently up and running and bug-free:

> There is no risk at this time with using Sushi Protocol, and the UI. All exposure to RouterProcessor2 has been removed from the front end, and all LPing / current swap activity is safe to do.
> 
> — I'm Software 🦇🔊 (@MatthewLilley) [April 9, 2023](https://twitter.com/MatthewLilley/status/1645116456269406212?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

> Previous 5 days, to be safe.
> 
> — Jared Grey (@jaredgrey) [April 9, 2023](https://twitter.com/jaredgrey/status/1645214249596092416?ref%5Fsrc=twsrc%5Etfw&ref=metatalks.ai)

External observers also signaled a resolution of the situation:

![](https://lh3.googleusercontent.com/FjTvyHks_lscSlVpIbOIRTfrW56rYg9kMFmHEZWHQgMB7puI4RsFwxvZjNdYgyTucrExypeGTz_JLdQVOyR-hYBht05a19GwFVv5mMtEjjf5HVrAbU4OZa5BTVdM_nvfBtqQGnrS8Xrz9_dcHUhA2jQ)

To conclude, another [educational thread](https://twitter.com/RisearmySP/status/1645068449477951488?ref=metatalks.ai) about interacting with DeFi and revoking methods and tools you can use:

![](https://lh5.googleusercontent.com/A15tYg0yBdWUqhDK19_-hlNwuZVH-fT0ITZdPU2AIxvXBoHNwovN_NXS2v_l6hFogHN12NoB43ga6AqXGX0RY3gA8xkCYa0Jtm1RU-W99oodUY6X41K9JxetIa9QGFM3XomqfLgnKKFupfE7eQTN4lA)