Unizen 2024 external-call approval exploit
An unsafe external-call path in an Ethereum Unizen trade-aggregation contract exposed approved user assets. Security reports estimated approximately USD 2.1–2.18 million stolen, followed by a bounty and law-enforcement response, reimbursement commencement, partial recovery, contract updates, and resumed active operation.
Incident facts
- Incident title
- Unizen 2024 external-call approval exploit
- Bridge
- Unizen
- Incident date
- 2024-03-08
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum
- Affected assets
- USDT, DAI, USDC
- Attack category
- Smart Contract Bug
- Reported loss
- Approximately USD 2.1–2.18 million
- Amount confidence
- Medium
- Loss amount basis
- Mixed Sources
- Recovery
- Partial Recovery
- Reimbursement
- In Progress
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Unclear
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
SlowMist and other security reporting described approximately USD 2.1 million stolen, while later tracking described about USD 2.18 million in DAI-equivalent stolen funds.
Retain a narrow range because reports use different transaction snapshots and later stolen-fund totals.
USDT drained and converted to DAIapproximately USD 2.1 million
Conservative display amount.
later tracked stolen DAI-equivalent fundsapproximately USD 2.18 million
Upper tracked amount after later attacker movement.
Why this remains unresolved
- The official reimbursement post proves commencement for more than 99 percent of affected users, not final settlement for every wallet.
- Wallets above USD 750,000 were to be handled case by case and no reviewed completion statement was located.
- Most remaining stolen funds were later moved through Tornado Cash, so full attacker return is not established.
Timeline events
Unizen deployed critical updates and resumed operation2024-03
First-party and contemporaneous reporting described critical contract and application updates, while current documentation and audits support continued active operation.
Unizen external-call approval exploit occurred2024-03-08
An unsafe external-call path exposed assets approved to the affected Ethereum trade-aggregation contract.
Unizen incident and approval risk disclosed2024-03-09
PeckShield and Unizen communications warned users about the approval issue and the need to revoke the affected contract allowance.
Unizen offered bounty and engaged investigators2024-03-10
Unizen sent an on-chain message offering a 20 percent bounty and stated that law-enforcement and forensic specialists were involved.
Unizen announced immediate reimbursement plan2024-03-11
Unizen announced that more than 99 percent of affected users would be made whole, beginning with wallets losing USD 750,000 or less, while larger cases would be handled individually.
Unizen reimbursement distributions began2024-03-11
The official announcement stated that distributions would begin immediately using USDT or USDC and would be reviewed wallet by wallet.
Unizen reported partial recovery from four hackers2024-03-12
SlowMist reported that Unizen's CTO announced approximately USD 185,000 recovered from four hackers.
Remaining stolen funds moved through Tornado Cash2024-08-07
Later tracking reported the exploiter moving approximately USD 2.16 million in stolen funds through Tornado Cash, preventing any inference of full attacker return.
Evidence records
- Unizen reimbursement announcementUnizen · Tier 1 · High reliability · primary · 2024-03-11Claim scope: Reimbursement
Official announcement of immediate reimbursement for more than 99 percent of affected users and threshold handling.
- PeckShield Unizen approval-issue alertPeckShield · Tier 1 · High reliability · secondary · 2024-03-08Claim scope: Incident Case
Contemporaneous detection and revoke-approval warning.
- Unizen CTO incident-response updateMartin Granström / Unizen · Tier 1 · High reliability · primary · 2024-03-10Claim scope: Incident Case
First-party technical-response, investigator, and security-update context.
- Explained: The Unizen Hack, March 2024Halborn · Tier 1 · High reliability · secondary · 2024-03Claim scope: Incident Case
Independent technical root-cause and outcome analysis.
- SlowMist Monthly Security Report — March 2024SlowMist · Tier 1 · High reliability · secondary · 2024-04-01Claim scope: Recovery
Reports approximately USD 2.1 million loss and approximately USD 185,000 recovery from four hackers.
- Unizen Pledges Reimbursements After USD 2.1M LossCryptonews · Tier 2 · High reliability · secondary · 2024-03-11Claim scope: Reimbursement
Preserves the official embedded reimbursement statement and threshold details.
- Unizen Security AuditsUnizen · Tier 1 · High reliability · primary · 2026Claim scope: Restart
Current audit listing and post-incident active-operation evidence.
- Unizen hacker transfers USD 2.1M stolen funds to Tornado CashCointelegraph / TradingView · Tier 2 · High reliability · secondary · 2024-08-07Claim scope: Recovery
Later stolen-fund movement and unresolved recovery context.
- Unizen reimbursement announcementUnizen · Tier 1 · High reliability · primary · 2024-03-11Claim scope: Reimbursement
Event-scoped primary copy supporting Unizen's immediate reimbursement plan, more-than-99-percent coverage statement, threshold, and case-by-case handling.
- PeckShieldAlert Unizen exploiter Tornado Cash transferPeckShieldAlert · Tier 1 · High reliability · secondary · 2024-08-07Claim scope: Recovery
Direct security-monitoring observation that the Unizen exploiter-labeled address transferred 865.4 ETH, worth approximately USD 2.16 million, to Tornado Cash.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final total reimbursed across all wallets is not established.
- The final recovered amount beyond the approximately USD 185,000 reported in March is not established.
- Current active operation does not establish reimbursement completion.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.