Magpie Protocol 2024 MagpieRouterV2 exploit
A selector-position validation flaw in MagpieRouterV2 allowed an attacker to bypass transfer protections and drain approved assets from 221 wallets. Magpie reported USD 129,000 stolen, paused the dApp, fixed the vulnerable path, reimbursed every affected wallet in full, and later reopened after additional review and security work.
Incident facts
- Incident title
- Magpie Protocol 2024 MagpieRouterV2 exploit
- Bridge
- Magpie Protocol
- Incident date
- 2024-04-23
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Unknown
- Affected assets
- Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- USD 129,000 from 221 wallets
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- None
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Available
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Magpie's first-party postmortem reported USD 129,000 stolen from 221 wallets.
The canonical amount is the first-party total. The affected asset basket and chain-level allocation are not expanded beyond reviewed sources.
assets drained from 221 walletsUSD 129,000
Canonical incident amount from the first-party postmortem.
Timeline events
MagpieRouterV2 exploit occurred2024-04-23
An attacker exploited selector-position validation in MagpieRouterV2 and drained approved assets from 221 wallets.
The incident affected Magpie's router and approved user assets, not Wormhole's bridge reserves.
Magpie dApp paused during incident response2024-04-23
Magpie paused and shut down the dApp to stop additional losses while the vulnerable routing path was fixed.
All affected Magpie users reimbursed in full2024-04-26
Magpie reported that every affected wallet had been reimbursed with the original asset on the chain where the loss occurred.
This is reimbursement, not attacker return or recovered stolen funds.
Magpie published router-vulnerability postmortem2024-04-26
The first-party postmortem described the selector-position flaw, temporary mitigation, permanent fix, reimbursement, and planned audit and monitoring work.
Magpie returned to operation after remediation2024-05
A May 2024 first-party follow-up described the vulnerability as fixed, users as fully refunded within two weeks, and the protocol as safe to use while additional audits and monitoring integrations continued.
Month precision is used because a dedicated exact-date relaunch notice was not located.
Evidence records
- Magpie Protocol Smart Contract Vulnerability Post MortemMagpie Protocol · Tier 1 · High reliability · primary · 2024-04-26Claim scope: Incident Case
Primary source for root cause, USD 129,000 amount, 221 wallets, fix, pause, and full reimbursement.
- Magpie Protocol Charting A Secure Path Following ExploitMagpie Protocol · Tier 1 · High reliability · primary · 2024-05-21Claim scope: Restart
Follow-up confirming full refunds within two weeks and continued security work.
- Magpie Protocol Smart Contract Vulnerability Post MortemMagpie Protocol · Tier 1 · High reliability · primary · 2024-04-26Claim scope: Incident Case
Event-scoped duplicate supporting the MagpieRouterV2 exploit, affected wallets, and amount.
- Magpie Protocol Smart Contract Vulnerability Post MortemMagpie Protocol · Tier 1 · High reliability · primary · 2024-04-26Claim scope: Shutdown
Event-scoped duplicate supporting the Magpie dApp pause during containment.
- Magpie Protocol Charting A Secure Path Following ExploitMagpie Protocol · Tier 1 · High reliability · primary · 2024-05-21Claim scope: Shutdown
Event-scoped duplicate independently supporting the incident-response shutdown before relaunch.
- Magpie Protocol Smart Contract Vulnerability Post MortemMagpie Protocol · Tier 1 · High reliability · primary · 2024-04-26Claim scope: Reimbursement
Event-scoped duplicate supporting full reimbursement with original assets.
- Magpie Protocol Charting A Secure Path Following ExploitMagpie Protocol · Tier 1 · High reliability · primary · 2024-05-21Claim scope: Reimbursement
Event-scoped duplicate independently confirming completion of full refunds.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The first-party sources do not provide a stable asset-by-asset and chain-by-chain incident table.
- The exact operational date on which the dApp reopened is described by follow-up state rather than a dedicated relaunch notice.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.