Renegade.fi has recovered about $190,000 after a whitehat hacker exploited a vulnerability in one of its Arbitrum-based dark pools and later returned more thanRenegade.fi has recovered about $190,000 after a whitehat hacker exploited a vulnerability in one of its Arbitrum-based dark pools and later returned more than

Renegade recovers $190K after whitehat returns stolen crypto

2026/05/11 15:08
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

Renegade.fi has recovered about $190,000 after a whitehat hacker exploited a vulnerability in one of its Arbitrum-based dark pools and later returned more than 90% of the stolen assets.

Summary
  • Renegade recovered about $190,000 after a white hat hacker returned more than 90% of the stolen funds.
  • The exploit targeted a faulty function tied to Renegade’s V1 Arbitrum dark pool.

Blockchain security firm Blockaid said the exploit drained roughly $209,000 from Renegade’s V1 Arbitrum dark pool at 8:27 am UTC on Sunday after an attacker injected malicious logic into a faulty function tied to the protocol’s resolver infrastructure. 

Arbiscan data showed that about $190,000 was later sent back to the wallet address “0xE4A…5CFBE,” including $84,370 in USDC (USDC), $27,885 in wrapped Bitcoin, and $23,950 in wrapped Ether.

In an on-chain message sent after the attack, Renegade offered the exploiter a 10% “whitehat bounty” in exchange for returning the remaining funds and warned that failure to cooperate could expose them to potential “civil or criminal action.” Within 45 minutes, the attacker transferred back more than 90% of the assets.

“I’ve seen a lot of contempt toward my actions,” the whitehat wrote in a response shared onchain. 

“Although I understand that what I did was not ethical, in the current DeFi cybersecurity, I believe this was the best solution to protect users’ funds and ensure their safety.”

Another message from the exploiter said the vulnerability was “tooooo simple and bad,” while also claiming that North Korean-linked hackers “would never come to negotiate.”

Faulty migration exposed Arbitrum dark pool

Renegade has confirmed that the incident stemmed from deployment code that failed to assign an explicit owner to the contract, combined with a faulty migration introduced during an April 2025 software update. 

According to the protocol, the flaw allowed anyone to rewrite the smart contract connected to its V1 Arbitrum dark pool.

Dark pools allow large traders to execute transactions privately without exposing order size or direction to the open market. Renegade said only 7% of its trading activity passed through the affected V1 Arbitrum pool and added that impacted users would be compensated directly.

A post-mortem and “full root-cause analysis” are expected to be released by the protocol in the coming days.

Recent exploits involving resolver systems, proxy contracts, and admin permissions have pushed fresh scrutiny onto DeFi infrastructure design. 

On May 7, liquidity provider TrustedVolumes lost roughly $5.87 million after attackers targeted a custom RFQ swap proxy tied to 1inch infrastructure. Blockaid linked the attacker to the March 2025 1inch Fusion V1 exploit, although it said the newer incident relied on a separate vulnerability involving the proxy setup.

Debate over contract risk intensified further after 1inch co-founder Sergej Kunz criticized shared-pool lending systems following the Kelp DAO rsETH exploit that disrupted liquidity on Aave. 

Kunz argued that “one weak collateral listing can affect an entire reserve” and later promoted intent-based lending systems where users negotiate fixed loan terms without relying on shared liquidity pools.

Separate reporting from crypto.news also showed that Wasabi Protocol lost more than $5 million across Ethereum, Base, Berachain, and Blast after security firms identified a compromised admin key that allowed attackers to upgrade contracts and drain funds.

시장 기회
Based 로고
Based 가격(BASED)
$0.07952
$0.07952$0.07952
-1.32%
USD
Based (BASED) 실시간 가격 차트

SPACEX(PRE) Launchpad Is Live

SPACEX(PRE) Launchpad Is LiveSPACEX(PRE) Launchpad Is Live

Start with $100 to share 6,000 SPACEX(PRE)

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!