logo

Dough Finance Incident Analysis

ID: 68ad3fbb-02cc-520e-876e-4557014949bf

STIX ID: report--68ad3fbb-02cc-520e-876e-4557014949bf

Feed Name: CertiK Blog

Threat Score
75/100

Date Published: 2024-07-16

Date Updated: 2026-06-11

...
...

On 12 July 2024 Dough Finance was exploited for approximately $2.1M after an attacker used flash loans and crafted paraswap calldata to trigger transferFrom calls in the ConnectorDeleverageParaswap deloop flow, draining WETH from multiple Dough DSA contracts; some funds were swapped and laundered via Tornado Cash while a white-hat returned a portion of ETH. The root cause is improper calldata validation in the call chain (deloopInOneOrMultipleTransactions → deloopAllCollaterals → flashloanVars.paraSwapContract.call), and the report includes addresses, transaction hashes, fund flows, and partial recoveries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.