The encyclopedia · Finance & Accounting · Technical decision · 2023
Euler lost $197M to a missing check — then the attacker gave it back
On March 13, 2023 an exploit drained $197M from Euler. What followed was a three-week on-chain negotiation — and a 100% recovery.
Euler Finance · 2023-03-13
What happened
Euler was a decentralized lending protocol on Ethereum. Its donateToReserves function had been patched in July 2022 to fix one bug — but the patch left out a health check.
On 13 March 2023, starting at 8:50 UTC, an attacker borrowed around $30 million of DAI in a flash loan, deposited $20 million into Euler, leveraged the position to roughly ten times the deposit, then used donateToReserves to destroy their own collateral while leaving the debt intact — making themselves eligible for liquidation and claiming a liquidation bonus larger than the cost of the donation. About $197 million in USDC, wrapped bitcoin, staked ether and DAI left the protocol; Euler's EUL token fell more than 45 per cent.
What followed was a negotiation. Euler messaged the exploiter on-chain and demanded the return of 90 per cent of the funds within 24 hours, threatening a $1 million reward for information leading to an arrest. The attacker — communicating as 'Jacob' by on-chain messages and email — returned funds in tranches: 3,000 ETH on 18 March, 51,000 ETH on 25 March, apologising on-chain ('I messed up') as the recovery reached about 84 per cent. Along the way, the Lazarus Group tried to counter-exploit the attacker with a malicious decryption link; Euler warned its own exploiter not to open it.
On 3 April 2023 the final tranches came back, and on 4 April Euler announced a full recovery: roughly $240 million returned — more than was taken, because the stolen assets had appreciated during the negotiation. It stood as one of the largest recoveries in DeFi history: the exploit cost the protocol everything for three weeks, and in the end nothing.
Why it happened
- A patch against one bug shipped without the health check that would have caught the next one.
- The exploit chained a flash loan, 10x self-leverage and a donate-to-reserves trick into a $197M drain — one transaction family, no forced entry.
- The recovery came from negotiation, not force: an ultimatum, on-chain messages, and tranches returned over three weeks.
The lesson
Every patch is a new surface: the function Euler fixed in July carried the flaw exploited in March. The second lesson is rarer: the attacker gave the money back.
Sources
- Euler Finance — War & Peace: Behind the Scenes of Euler's $240M Exploit Recovery
- Chainalysis — Euler Finance Flash Loan Attack Explained
spotted an error? The club wants to know.
More like this
Beanstalk let a flash loan vote — and a $1B loan passed the budget
Mango Markets was drained of $110M by its own collateral rule
Allen Stanford's $7B Ponzi scheme — 110 years, 28,000 victims
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.