Analysis of the Steadefi Exploit

Learn how Steadefi was exploited on multiple chains, resulting in a loss of $1.14 million.


On August 7, 2023, Steadefi was exploited on the Arbitrum and Avalanche chains, which resulted in a loss of assets worth approximately $1.14 million.

Introduction to Steadefi#

Steadefi is the DeFi protocol designed to provide the highest and most sustainable real yields to investors without the stress of constant position management or the prolonged downturns of the crypto markets.

Vulnerability Assessment#

The root cause of the exploit is due to the compromise of the private keys.


Step 1:

According to the team, their protocol deployer wallet was compromised. This wallet address was also the owner of all vaults in the protocol.

Step 2:

The exploiter then transferred ownership of the vaults in succession, including lending and strategy, to a wallet they controlled and went on to take various owner-only actions, such as allowing any wallet to borrow any available funds from the lending vaults.

Step 3:

The exploiter first approved themselves as borrowers on Arbitrum and then on Avalanche, then proceeded to borrow tokens from these chains subsequently. This process was repeated multiple times.

Step 4:

The attacker then drained all available lending capacity on both the Arbitrum and the Avalanche chains, swapped the stolen assets to ETH, and then bridged them to Ethereum.

Step 5:

At the time of writing, the attacker is in control of all the stolen money at this address.


Following the incident, the team acknowledged the occurrence of the exploit and stated that they had sent an on-chain message to the attacker’s wallet address for a possible negotiation.

The TVL of the project dropped from $2.03 million to $669,000 following the exploit.


