Refreshed 3h ago· updates every 6h

Furucombo (2021) — Crypto Hack

Laundered
Feb 27, 2021·
Ethereum
Amount Stolen
$14.0M
~$14M in various ERC-20 tokens
Recovered
$0

Furucombo was drained via a 'evil contract' trick where the attacker registered a malicious Aave V2 implementation, stealing approved tokens from users.

Summary

Furucombo was drained via a 'evil contract' trick where the attacker registered a malicious Aave V2 implementation, stealing approved tokens from users.

How It Was Compromised — DeFi via Smart Contract Exploit

DeFiSmart Contract Exploit

The attacker tricked Furucombo's proxy contract into thinking a malicious contract was a legitimate Aave V2 implementation. The proxy delegatecalled to the evil contract, which then used existing token approvals that users had granted to Furucombo to drain their wallets. All affected users had previously approved Furucombo to spend their tokens.

Fund Flow & Laundering Analysis

Stolen tokens immediately swapped to ETH via Uniswap and deposited to Tornado Cash. Furucombo team published a full post-mortem and issued COMBO tokens as partial compensation. The attacker profited approximately $14M net after flash loan costs. No attacker identification made. Funds laundered via Tornado Cash.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.