Incident case

Magpie Protocol 2024 MagpieRouterV2 exploit

A selector-position validation flaw in MagpieRouterV2 allowed an attacker to bypass transfer protections and drain approved assets from 221 wallets. Magpie reported USD 129,000 stolen, paused the dApp, fixed the vulnerable path, reimbursed every affected wallet in full, and later reopened after additional review and security work.

fullcurrent

Incident facts

Incident title
Magpie Protocol 2024 MagpieRouterV2 exploit
Bridge
Magpie Protocol
Incident date
2024-04-23
Incident type
Exploit
Major incident
Yes
Affected chains
Unknown
Affected assets
Unknown
Attack category
Smart Contract Bug
Reported loss
USD 129,000 from 221 wallets
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
None
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Available
Resolution
Final outcome known
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

Magpie's first-party postmortem reported USD 129,000 stolen from 221 wallets.

The canonical amount is the first-party total. The affected asset basket and chain-level allocation are not expanded beyond reviewed sources.

Timeline events

  • MagpieRouterV2 exploit occurred2024-04-23

    An attacker exploited selector-position validation in MagpieRouterV2 and drained approved assets from 221 wallets.

    Exploit OccurredHigh

    The incident affected Magpie's router and approved user assets, not Wormhole's bridge reserves.

  • Magpie dApp paused during incident response2024-04-23

    Magpie paused and shut down the dApp to stop additional losses while the vulnerable routing path was fixed.

    Bridge PausedHigh
  • All affected Magpie users reimbursed in full2024-04-26

    Magpie reported that every affected wallet had been reimbursed with the original asset on the chain where the loss occurred.

    Reimbursement CompletedHigh

    This is reimbursement, not attacker return or recovered stolen funds.

  • Magpie published router-vulnerability postmortem2024-04-26

    The first-party postmortem described the selector-position flaw, temporary mitigation, permanent fix, reimbursement, and planned audit and monitoring work.

    Postmortem PublishedHigh
  • Magpie returned to operation after remediation2024-05

    A May 2024 first-party follow-up described the vulnerability as fixed, users as fully refunded within two weeks, and the protocol as safe to use while additional audits and monitoring integrations continued.

    Bridge ReopenedMedium

    Month precision is used because a dedicated exact-date relaunch notice was not located.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.