On 28 Feb, an exploit hit the Seneca stablecoin protocol, resulting in a loss exceeding $6 million across Ethereum and Arbitrum networks. It turns out an unknown attacker exploited a bug in the smart contract approval mechanism, which allowed funds to be diverted. Despite accessing roughly $6 million in ETH through the exploit, the hacker has returned 80% of the money after receiving a bounty offer.
Why did the Seneca exploit happen?
CertiK and other companies alerted users to the exploit, advising them to revoke approvals linked to a specific address on both the Ethereum and Arbitrum networks. Initially estimated at million, the losses later exceeded 1,900 Ether, valued at approximately $6.4 million.
According to security analysts at Blocksec, the breach stemmed from an “arbitrary call issue” within Seneca’s smart contracts. Seneca’s contracts didn’t have pause functionality, so users had to revoke permissions.
By exploiting this flaw, the attacker was able to transfer tokens unauthorized to external addresses. Lei Wu, Blocksec’s CTO explained, “The root cause was an arbitrary call issue, allowing approvals to be transferred out to the vulnerable contract.”
Seneca offered a $1.2 million bounty for the return of the stolen funds. In a message posted on-chain on February 29, Seneca proposed that the hacker return 80% of the stolen funds to an Ethereum address, allowing them to retain the remaining 20%.
How much was recovered?
After the incident, the Seneca team said they knew about it. They told users to cancel any permissions they gave before, to stop more unauthorized transactions from happening.
The Seneca token experienced a drastic decline of over 60% subsequent to the exploit, plummeting from approximately $0.1 to below $0.04. Currently, SEN is being traded at $0.04428, indicating a significant drop of 46.27% within the last day.
Seneca assures saying they are working with security firms and law enforcement agencies to track the money. In order to avoid legal repercussions, the perpetrator was pleaded to return the money. “Taking swift action is imperative, thus we respectfully urge the return of the funds promptly to prevent any further legal measures,” they emphasized.
Shortly after Seneca’s announcement, the hacker returned roughly 1,537 ETH, valued at around $5.3 million, to the specified wallet address. Retaining 300 ETH, equivalent to approximately $1 million, the exploiter accepted Seneca’s 20% bounty. Subsequently, the exploiter transferred the ETH to two distinct addresses.
