logo

Initialization Oversight: The Merlin DEX Exploit

ID: 159862e5-ea9f-5279-b80c-372bc853c02d

STIX ID: report--159862e5-ea9f-5279-b80c-372bc853c02d

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2024-01-08

Date Updated: 2026-06-11

...
...

Merlin DEX was exploited on April 26, 2023 after an initialization bug in the MerlinSwapPair contract granted maximum token allowances to the factory's feeTo role, allowing the deployer to withdraw all reserves and drain 435 WETH and 811,000 USDC; the flaw was identified within CertiK's audit scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.