Grafa
Whitehat returns most funds after Renegade exploit
Whitehat returns most funds after Renegade exploit

Whitehat returns most funds after Renegade exploit

Share

Renegade said a whitehat hacker returned roughly $190,000 after exploiting vulnerabilities tied to one of the protocol’s Arbitrum-based decentralised dark pools.

Blockchain security platform Blockaid initially flagged the exploit, which reportedly involved malicious logic being injected into a faulty function linked to Renegade’s V1 Arbitrum dark pool.

The attacker stole 27 ERC-20 tokens before later returning more than 90% of the funds, including holdings denominated in USDC, wrapped Bitcoin and wrapped Ethereum.

In an onchain message, Renegade requested that the hacker return most of the assets and retain 10% as a whitehat bounty in exchange for avoiding potential legal action.

“I believe this was the best solution to protect users' funds and ensure their safety,”

The whitehat hacker responded while criticising the protocol’s weak security design.

Renegade later said the vulnerability stemmed from deployment code that failed to assign an explicit owner combined with a faulty migration process introduced during an April 2025 software update.

The protocol added that affected users would be fully compensated and noted that only around 7% of trading activity passed through the compromised V1 Arbitrum dark pool.

The incident highlighted the growing role of whitehat hackers within decentralised finance as protocols increasingly rely on ethical hackers and coordinated disclosure frameworks to identify vulnerabilities before malicious actors exploit them.

At the time of reporting, Bitcoin price was $80,841.58.

Frequently asked questions

Connect with us

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.