Renegade Recovers $190K After Whitehat Returns Stolen Crypto

Renegade Recovers $190K After Whitehat Returns Stolen Crypto

N
News Editor 01
2026-07-23 06:10:15
A whitehat hacker drained ~$209K from Renegade’s V1 Arbitrum dark pool but returned over 90% after a 10% bounty offer. The flaw originated from migration code that failed to assign a contract owner.
Renegadedark poolwhitehat hackerDeFi securityArbitrum

Renegade.fi has recovered approximately $190,000 after a whitehat hacker exploited a vulnerability in one of its Arbitrum-based dark pools and later returned more than 90% of the stolen assets. The incident initially drained roughly $209,000 from the protocol's V1 Arbitrum dark pool at 8:27 am UTC on Sunday, according to blockchain security firm Blockaid. The attacker injected malicious logic into a faulty function tied to the protocol's resolver infrastructure.

Arbiscan data shows about $190,000 was later sent back to the wallet address “0xE4A…5CFBE,” including $84,370 in USDC, $27,885 in wrapped Bitcoin, and $23,950 in wrapped Ether. After the attack, Renegade offered a 10% “whitehat bounty” via an on-chain message, warning that failure to cooperate could lead to civil or criminal action. Within 45 minutes, the attacker returned more than 90% of the funds.

“I’ve seen a lot of contempt toward my actions,” the whitehat wrote in an on-chain response. “Although I understand that what I did was not ethical, in the current DeFi cybersecurity, I believe this was the best solution to protect users’ funds and ensure their safety.” Another message called the vulnerability “tooooo simple and bad” and claimed that North Korean-linked hackers “would never come to negotiate.”

Root Cause: Migration Code Without an Owner

Renegade confirmed the exploit stemmed from deployment code that failed to assign an explicit owner to the contract, combined with a faulty migration introduced during an April 2025 software update. The flaw allowed anyone to rewrite the smart contract connected to its V1 Arbitrum dark pool. Dark pools let large traders execute privately without exposing order size or direction. The protocol said only 7% of its trading activity passed through the affected V1 pool and promised direct compensation for impacted users.

DeFi Attack Spree Puts Smart Contract Design Under Scrutiny

Recent exploits involving resolver systems, proxy contracts, and admin permissions have drawn fresh attention to DeFi infrastructure. On May 7, liquidity provider TrustedVolumes lost roughly $5.87 million after attackers targeted a custom RFQ swap proxy tied to 1inch infrastructure. Blockaid linked the attacker to the March 2025 1inch Fusion V1 exploit but said this incident relied on a separate proxy vulnerability. 1inch co-founder Sergej Kunz criticized shared-pool lending after the Kelp DAO rsETH exploit disrupted Aave liquidity, arguing that “one weak collateral listing can affect an entire reserve” and promoting intent-based lending systems. Separately, Wasabi Protocol lost over $5 million across Ethereum, Base, Berachain, and Blast after an admin key compromise allowed attackers to upgrade contracts and drain funds. Renegade said a full post-mortem and root-cause analysis will be released in the coming days.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.