DeFi Platform Seneca Exploited for $6.4M, but Hacker Returns 80%

Decentralized lending platform Seneca has been the victim of an exploit that resulted in the loss of approximately $6.4 million in funds.

The incident occurred when an attacker compromised a vulnerability in the protocol’s ‘performOperations’ function, allowing him to drain more than $6 million in collateral from the platform.

This has raised significant concern in the DeFi community, highlighting the risks associated with security in the decentralized financial ecosystem.

The exploitation was carried out by transferring assets from Seneca’s collateral pools via calls to the ‘performOperations’ function.

According to the CertiK report, this malicious action was possible due to a bug in the protocol code, which allowed the attacker to make external calls to any address, completely controlling the call data.

Seneca reportedly suffers from an additional vulnerability that prevents developers from pausing contracts

However, there was an unexpected twist when the attacker returned 80% of the stolen funds after the Seneca team offered a reward.

Through a whitehat request, approximately $5.3 million was recovered, an optimistic scenario in the midst of the crisis.

While this act brought some relief, it also highlights the importance of collaboration between project teams and potential attackers to mitigate damage.

Importantly, the company had conducted a security audit prior to the launch of its Chamber contract, in an attempt to ensure the integrity of the protocol.

However, as has been demonstrated, an audit is not an absolute guarantee of security.

This raises questions about the effectiveness of audit processes and the need to take additional measures to strengthen security in the DeFi ecosystem.

The security incident at Seneca highlights persistent challenges in the DeFi space and underscores the importance of continued vigilance and collaboration among industry players to protect user funds and strengthen trust in these decentralized financial platforms.


