Incident case

Unizen 2024 external-call approval exploit

An unsafe external-call path in an Ethereum Unizen trade-aggregation contract exposed approved user assets. Security reports estimated approximately USD 2.1–2.18 million stolen, followed by a bounty and law-enforcement response, reimbursement commencement, partial recovery, contract updates, and resumed active operation.

reviewedcurrent

Incident facts

Incident title
Unizen 2024 external-call approval exploit
Bridge
Unizen
Incident date
2024-03-08
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDT, DAI, USDC
Attack category
Smart Contract Bug
Reported loss
Approximately USD 2.1–2.18 million
Amount confidence
Medium
Loss amount basis
Mixed Sources
Recovery
Partial Recovery
Reimbursement
In Progress
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Unclear
Resolution
Unresolved
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

SlowMist and other security reporting described approximately USD 2.1 million stolen, while later tracking described about USD 2.18 million in DAI-equivalent stolen funds.

Retain a narrow range because reports use different transaction snapshots and later stolen-fund totals.

Why this remains unresolved

Timeline events

  • Unizen deployed critical updates and resumed operation2024-03

    First-party and contemporaneous reporting described critical contract and application updates, while current documentation and audits support continued active operation.

    Bridge ReopenedMedium
  • Unizen external-call approval exploit occurred2024-03-08

    An unsafe external-call path exposed assets approved to the affected Ethereum trade-aggregation contract.

    Exploit OccurredHigh
  • Unizen incident and approval risk disclosed2024-03-09

    PeckShield and Unizen communications warned users about the approval issue and the need to revoke the affected contract allowance.

    Hack DisclosedHigh
  • Unizen offered bounty and engaged investigators2024-03-10

    Unizen sent an on-chain message offering a 20 percent bounty and stated that law-enforcement and forensic specialists were involved.

    Legal ActionHigh
  • Unizen announced immediate reimbursement plan2024-03-11

    Unizen announced that more than 99 percent of affected users would be made whole, beginning with wallets losing USD 750,000 or less, while larger cases would be handled individually.

    Reimbursement AnnouncedHigh
  • Unizen reimbursement distributions began2024-03-11

    The official announcement stated that distributions would begin immediately using USDT or USDC and would be reviewed wallet by wallet.

    Reimbursement StartedHigh
  • Unizen reported partial recovery from four hackers2024-03-12

    SlowMist reported that Unizen's CTO announced approximately USD 185,000 recovered from four hackers.

    Funds RecoveredHigh
  • Remaining stolen funds moved through Tornado Cash2024-08-07

    Later tracking reported the exploiter moving approximately USD 2.16 million in stolen funds through Tornado Cash, preventing any inference of full attacker return.

    OtherHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.