Back to dashboard
Saturday, April 18, 2020 at 22:58 UTC

Lendf.Me

ERC-777 reentrancy; attacker returned funds.

Recovered
Funds stolen
$25.00M
Recovered
$25.00M100%
Still outstanding
$0.00M
Chain
Ethereum
Category
DeFi
Attack vector
Reentrancy
Reported by
PeckShield
Incident ID
h2020-2

Exploit & recovery timeline

  1. Apr 18, 2020 · 20:58 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the reentrancy exploit against Lendf.Me.

  2. Apr 18, 2020 · 22:58 UTC
    Exploit executed

    $25.0M drained from Lendf.Me on Ethereum via Reentrancy.

  3. Apr 18, 2020 · 23:58 UTC
    Detected by PeckShield

    PeckShield flagged the anomalous transactions and published an initial alert.

  4. Apr 19, 2020 · 02:58 UTC
    Protocol response

    Lendf.Me paused affected contracts or withdrawals and began tracing outbound flows.

  5. Apr 19, 2020 · 22:58 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. Apr 25, 2020 · 22:58 UTC
    Full recovery

    $25.0M returned to users — negotiation, freezes, or a whitehat return closed the incident.