SSS DeFi (2026) — Crypto Hack
ActiveICP-based DeFi protocol SSS DeFi was drained of ~$9,204 due to a CLMM position creation/exit calculation inconsistency that allowed an attacker to create abnormal liquidity entitlements and drain real assets. 19 abnormal Open/Burn groups and 58 withdrawals were executed. Preparation funds traced to Tornado Cash.
Summary
ICP-based DeFi protocol SSS DeFi was drained of ~$9,204 due to a CLMM position creation/exit calculation inconsistency that allowed an attacker to create abnormal liquidity entitlements and drain real assets. 19 abnormal Open/Burn groups and 58 withdrawals were executed. Preparation funds traced to Tornado Cash.
How It Was Compromised — DeFi via CLMM Position Calculation Inconsistency
SSS DeFi, an Internet Computer (ICP)-based decentralized finance protocol, suffered a security incident on July 28, 2026, resulting in the loss of approximately $9,204. While the financial impact was small, the exploit is notable as one of the first documented DeFi exploits on the Internet Computer platform. The root cause was a Concentrated Liquidity Market Maker (CLMM) position creation and exit calculation inconsistency that allowed an attacker to create abnormal liquidity entitlements and drain real assets from the protocol. The attacker executed 19 abnormal Open/Burn groups and 58 withdrawals across BTC, BNB, and SOL pools. Investigation traced the preparation funds used for the attack to Tornado Cash, a known cryptocurrency mixing service.
Fund Flow & Laundering Analysis
Preparation funds for the attack were traced to Tornado Cash. Stolen funds were withdrawn across BTC, BNB, and SOL pools, with 58 separate withdrawals executed to disperse the stolen assets.