Back to the archive

The encyclopedia · Finance & Accounting · Technical decision · 2023

Euler lost $197M to a missing check — then the attacker gave it back

On March 13, 2023 an exploit drained $197M from Euler. What followed was a three-week on-chain negotiation — and a 100% recovery.

Euler Finance · 2023-03-13

What happened

Euler was a decentralized lending protocol on Ethereum. Its donateToReserves function had been patched in July 2022 to fix one bug — but the patch left out a health check.

On 13 March 2023, starting at 8:50 UTC, an attacker borrowed around $30 million of DAI in a flash loan, deposited $20 million into Euler, leveraged the position to roughly ten times the deposit, then used donateToReserves to destroy their own collateral while leaving the debt intact — making themselves eligible for liquidation and claiming a liquidation bonus larger than the cost of the donation. About $197 million in USDC, wrapped bitcoin, staked ether and DAI left the protocol; Euler's EUL token fell more than 45 per cent.

What followed was a negotiation. Euler messaged the exploiter on-chain and demanded the return of 90 per cent of the funds within 24 hours, threatening a $1 million reward for information leading to an arrest. The attacker — communicating as 'Jacob' by on-chain messages and email — returned funds in tranches: 3,000 ETH on 18 March, 51,000 ETH on 25 March, apologising on-chain ('I messed up') as the recovery reached about 84 per cent. Along the way, the Lazarus Group tried to counter-exploit the attacker with a malicious decryption link; Euler warned its own exploiter not to open it.

On 3 April 2023 the final tranches came back, and on 4 April Euler announced a full recovery: roughly $240 million returned — more than was taken, because the stolen assets had appreciated during the negotiation. It stood as one of the largest recoveries in DeFi history: the exploit cost the protocol everything for three weeks, and in the end nothing.

Why it happened

  • A patch against one bug shipped without the health check that would have caught the next one.
  • The exploit chained a flash loan, 10x self-leverage and a donate-to-reserves trick into a $197M drain — one transaction family, no forced entry.
  • The recovery came from negotiation, not force: an ultimatum, on-chain messages, and tranches returned over three weeks.
What it cost$197M exploited — 100% recoveredcostly

The lesson

Every patch is a new surface: the function Euler fixed in July carried the flaw exploited in March. The second lesson is rarer: the attacker gave the money back.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →