Unizen 2024 external-call approval exploit
An unsafe external-call path in an Ethereum Unizen trade-aggregation contract exposed approved user assets. Security reports estimated approximately USD 2.1–2.18 million stolen, followed by a bounty and law-enforcement response, reimbursement commencement, partial recovery, contract updates, and resumed active operation.
Incident facts
- Incident title
- Unizen 2024 external-call approval exploit
- Bridge
- Unizen
- Incident date
- 2024-03-08
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum
- Affected assets
- USDT, DAI, USDC
- Attack category
- Smart Contract Bug
- Reported loss
- Approximately USD 2.1–2.18 million
- Recovery
- Partial Recovery
- Reimbursement
- In Progress
- Restart
- Reopened
- Current outcome
- Active After Incident
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Timeline events
Unizen deployed critical updates and resumed operation2024-03
First-party and contemporaneous reporting described critical contract and application updates, while current documentation and audits support continued active operation.
Unizen external-call approval exploit occurred2024-03-08
An unsafe external-call path exposed assets approved to the affected Ethereum trade-aggregation contract.
Unizen incident and approval risk disclosed2024-03-09
PeckShield and Unizen communications warned users about the approval issue and the need to revoke the affected contract allowance.
Unizen offered bounty and engaged investigators2024-03-10
Unizen sent an on-chain message offering a 20 percent bounty and stated that law-enforcement and forensic specialists were involved.
Unizen announced immediate reimbursement plan2024-03-11
Unizen announced that more than 99 percent of affected users would be made whole, beginning with wallets losing USD 750,000 or less, while larger cases would be handled individually.
Unizen reimbursement distributions began2024-03-11
The official announcement stated that distributions would begin immediately using USDT or USDC and would be reviewed wallet by wallet.
Unizen reported partial recovery from four hackers2024-03-12
SlowMist reported that Unizen's CTO announced approximately USD 185,000 recovered from four hackers.
Remaining stolen funds moved through Tornado Cash2024-08-07
Later tracking reported the exploiter moving approximately USD 2.16 million in stolen funds through Tornado Cash, preventing any inference of full attacker return.
Evidence records
- Unizen reimbursement announcementUnizen · Tier 1 · 2024-03-11
- PeckShield Unizen approval-issue alertPeckShield · Tier 1 · 2024-03-08
- Unizen CTO incident-response updateMartin Granström / Unizen · Tier 1 · 2024-03-10
- Explained: The Unizen Hack, March 2024Halborn · Tier 1 · 2024-03
- SlowMist Monthly Security Report — March 2024SlowMist · Tier 1 · 2024-04-01
- Unizen Pledges Reimbursements After USD 2.1M LossCryptonews · Tier 2 · 2024-03-11
- Unizen Security AuditsUnizen · Tier 1 · 2026
- Unizen hacker transfers USD 2.1M stolen funds to Tornado CashCointelegraph / TradingView · Tier 2 · 2024-08-07
Known unknowns
- The final total reimbursed across all wallets is not established.
- The final recovered amount beyond the approximately USD 185,000 reported in March is not established.
- Current active operation does not establish reimbursement completion.