Magpie Protocol 2024 MagpieRouterV2 exploit
A selector-position validation flaw in MagpieRouterV2 allowed an attacker to bypass transfer protections and drain approved assets from 221 wallets. Magpie reported USD 129,000 stolen, paused the dApp, fixed the vulnerable path, reimbursed every affected wallet in full, and later reopened after additional review and security work.
Incident facts
- Incident title
- Magpie Protocol 2024 MagpieRouterV2 exploit
- Bridge
- Magpie Protocol
- Incident date
- 2024-04-23
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Unknown
- Affected assets
- Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- USD 129,000 from 221 wallets
- Recovery
- None
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Timeline events
MagpieRouterV2 exploit occurred2024-04-23
An attacker exploited selector-position validation in MagpieRouterV2 and drained approved assets from 221 wallets.
Magpie dApp paused during incident response2024-04-23
Magpie paused and shut down the dApp to stop additional losses while the vulnerable routing path was fixed.
All affected Magpie users reimbursed in full2024-04-26
Magpie reported that every affected wallet had been reimbursed with the original asset on the chain where the loss occurred.
Magpie published router-vulnerability postmortem2024-04-26
The first-party postmortem described the selector-position flaw, temporary mitigation, permanent fix, reimbursement, and planned audit and monitoring work.
Magpie returned to operation after remediation2024-05
A May 2024 first-party follow-up described the vulnerability as fixed, users as fully refunded within two weeks, and the protocol as safe to use while additional audits and monitoring integrations continued.
Evidence records
- Magpie Protocol Smart Contract Vulnerability Post MortemMagpie Protocol · Tier 1 · 2024-04-26
- Magpie Protocol Charting A Secure Path Following ExploitMagpie Protocol · Tier 1 · 2024-05-21
Known unknowns
- The first-party sources do not provide a stable asset-by-asset and chain-by-chain incident table.
- The exact operational date on which the dApp reopened is described by follow-up state rather than a dedicated relaunch notice.