Velocore (2024) — Crypto Hack
LaunderedVelocore, a DEX operating on Linea and zkSync, was exploited for ~$6.8M through a vulnerability in its liquidity pool contracts.
Summary
Velocore, a DEX operating on Linea and zkSync, was exploited for ~$6.8M through a vulnerability in its liquidity pool contracts.
How It Was Compromised — DeFi via Smart Contract Exploit
On June 8, 2024, Velocore, a decentralized exchange operating on Linea and zkSync, was exploited for approximately $6.8M. The attacker identified a vulnerability in the protocol's liquidity pool contracts that allowed them to manipulate token balances and extract value from the pools. The exploit affected both the Linea and zkSync deployments. Velocore paused all operations and engaged with blockchain analytics firms to track the stolen funds.
Fund Flow & Laundering Analysis
Stolen tokens were swapped to ETH and stablecoins via decentralized exchanges on the affected chains. The funds were then bridged to Ethereum mainnet and deposited into Tornado Cash. The attacker used cross-chain bridges to fragment the laundering trail.