CSIDB logo
Incident

QuickSwap

Incident posture

Attack window
Oct 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
QuickSwap
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

QuickSwap Lend suffered a flash loan exploit resulting in approximately $220,000 in losses due to a vulnerability in the Curve Oracle utilized by Market XYZ's lending market. The attack exclusively impacted Market XYZ's operations, while QuickSwap's core contracts and other systems remained unaffected. Following the incident, the platform announced the closure of its lending service.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 24, 2022, QuickSwap publicly disclosed a security incident affecting its QuickSwap Lend service via a social media announcement. The platform confirmed that $220,000 was exploited through a flash loan attack targeting a vulnerability in the Curve Oracle implementation utilized by Market XYZ, a third-party lending market integrated with QuickSwap Lend. The attack specifically compromised Market XYZ's lending market operations but did not impact QuickSwap's core decentralized exchange contracts or other protocol infrastructure. QuickSwap attributed the exploit solely to the oracle vulnerability within Market XYZ's system, clarifying that no inherent flaws existed in their own audited smart contracts. The incident prompted the immediate decision to permanently discontinue QuickSwap Lend services to prevent further exposure, though existing liquidity pools and trading functions on QuickSwap remained operational throughout.

The financial impact was confined to the $220,000 loss directly attributable to the flash loan exploit within Market XYZ’s lending market. QuickSwap emphasized that user funds outside the compromised lending market were unaffected and reiterated the safety of its primary decentralized exchange operations. No collateral damage to other partnerships or integrated protocols was reported. In response, QuickSwap initiated service termination procedures for QuickSwap Lend while maintaining transparency about the incident’s scope through its official communication channels. The platform did not announce reimbursement plans or detailed forensic findings beyond confirming the oracle-related attack vector and third-party service involvement. Operations continued normally across all unaffected QuickSwap services following the lending market’s closure.

Sources

Sources available to members: 1 source.

CSIDB