{"investigation":{"slug":"dexible-v2","entity_name":"Dexible V2","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Dexible V2 is a multichain DEX aggregator that suffered a critical smart contract exploit on February 17, 2023, resulting in approximately $2 million in user funds stolen across Ethereum and Arbitrum. The attack exploited an unvalidated router address in the selfSwap function of the v2 contracts, which had never undergone a formal third-party security audit. Stolen funds were laundered through Tornado Cash and have not been recovered; the protocol has since ceased operations.","sections":[{"content":"On February 17, 2023, an attacker exploited a critical vulnerability in Dexible V2's selfSwap smart contract function, draining approximately $2 million from 17 user accounts across Ethereum and Arbitrum. The vulnerability resided in the selfSwap() and fill() functions of the v2 contracts, which allowed users to specify custom swap routing but performed no on-chain validation of the supplied router address. By submitting a crafted SelfSwap request that pointed to a malicious contract address instead of a legitimate DEX, the attacker caused the Dexible contract to execute a delegatecall that invoked transferFrom on any token contract where users had previously granted spend approval to Dexible. The attacker's address was 0x684083f312ac50f538cc4b634d85a2feafaab77a. Approximately $1.5 million was stolen on Ethereum mainnet and $450,000 on Arbitrum. The largest individual loss — roughly $1.4 million in TRU tokens (18 million TRU) — came from a single address attributed to blockchain investment firm BlockTower Capital. The team stated that 'a few whales' accounted for approximately 85% of total losses.","heading":"February 2023 Exploit — selfSwap Vulnerability","sources":[{"url":"https://rekt.news/dexible-rekt","name":"Dexible - REKT","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/tech/2023/02/17/blocktower-capital-loses-15m-in-defi-market-aggregator-dexible-exploit-blockchain-data","name":"BlockTower Capital Loses $1.5M in DeFi Market Aggregator Dexible Exploit — CoinDesk","type":"news_article","credibility":1},{"url":"https://blockapex.io/dexible-hack-analysis/","name":"Dexible Hack Analysis — BlockApex","type":"research","credibility":2},{"url":"https://cointelegraph.com/news/dexibleapp-aggregator-hacked-for-2m-via-selfswap-function","name":"Dexible aggregator hacked for $2M via 'selfSwap' function — CoinTelegraph","type":"news_article","credibility":1}],"severity":"critical"},{"content":"A formal third-party security audit was never performed on the Dexible V2 contracts before deployment. In the team's post-mortem report, they acknowledged this fact while attempting to justify the omission based on the experience of their engineering team, noting that the core engineer responsible had over 25 years of software development experience and that several community members and internal engineers had reviewed the code without identifying the vulnerability. The post-mortem stated: 'a formal audit was not performed on the latest set of contracts.' The rekt.news analysis characterized this as inadequate diligence and noted that a formal audit 'certainly helps' even for experienced teams. The vulnerability — an unvalidated external call — is a well-documented class of smart contract flaw that professional audit processes are specifically designed to detect.","heading":"Absence of Formal Security Audit","sources":[{"url":"https://rekt.news/dexible-rekt","name":"Dexible - REKT","type":"news_article","credibility":2},{"url":"https://blog.solidityscan.com/dexible-hack-analysis-never-blindly-trust-smart-contracts-c2aee7943c1a","name":"Dexible Hack Analysis — Never Blindly Trust Smart Contracts — SolidityScan","type":"research","credibility":2}],"severity":"high"},{"content":"Following the exploit, the attacker converted the stolen TRU tokens into ETH via SushiSwap, then routed the proceeds through the sanctioned crypto mixer Tornado Cash to obscure the transaction trail. Approximately $1.5 million in ETH was sent directly to Tornado Cash from the Ethereum mainnet portion of the theft. The Arbitrum portion (approximately $450,000) was first bridged to Binance Smart Chain before also being laundered through Tornado Cash. No portion of the stolen funds has been recovered. Tornado Cash was sanctioned by the U.S. Treasury Department's OFAC in August 2022, making use of it by the attacker consistent with deliberate efforts to evade asset recovery.","heading":"Fund Laundering via Tornado Cash","sources":[{"url":"https://rekt.news/dexible-rekt","name":"Dexible - REKT","type":"news_article","credibility":2},{"url":"https://quadrigainitiative.com/casestudy/dexibledexaggregatorselfswapexploit.php","name":"Feb 2023 - Dexible DEX Aggregator SelfSwap Exploit — Quadriga Initiative","type":"research","credibility":2},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash","type":"regulatory","credibility":1}],"severity":"critical"},{"content":"The Dexible team's incident response has been widely criticized for its delayed and inadequate communication. The exploit occurred on the morning of February 17, 2023. On-chain security firm PeckShield raised an alarm via Twitter approximately five hours before the Dexible team issued any official public statement. The official announcement was released more than nine hours after the initial exploit. During the window between the attack and the official response, the Dexible team's Twitter account continued to publish promotional content. CEO Michael Coon later stated that their Twitter channel 'was not able to respond in time' despite the tech lead discovering the attack early. When commenting publicly on the event, Dexible issued the statement 'There's no excuse for an exploit, but these things happen,' which commentators described as minimizing the severity of the incident.","heading":"Delayed Incident Response","sources":[{"url":"https://rekt.news/dexible-rekt","name":"Dexible - REKT","type":"news_article","credibility":2},{"url":"https://cointelegraph.com/news/dexibleapp-aggregator-hacked-for-2m-via-selfswap-function","name":"Dexible aggregator hacked for $2M via 'selfSwap' function — CoinTelegraph","type":"news_article","credibility":1}],"severity":"high"},{"content":"Following the exploit, Dexible paused its affected contracts. According to Crunchbase, Dexible is listed as permanently closed. Security researchers at Revoke.cash noted that affected users remained at risk as long as they had not revoked their token approvals to Dexible contracts, as the approval grants remained active on-chain regardless of the protocol's operational status. Revoke.cash maintained an exploit checker tool specifically for the Dexible incident to assist impacted users. The protocol's GitHub repository is housed under the 'thorium-dev-group' and 'BUIDLHub' organizations. No victim compensation fund or recovery program was established by the Dexible team. The protocol was active on six chains before closure: Ethereum, Arbitrum, Polygon, Avalanche, BNB Chain, and Fantom.","heading":"Protocol Status and Ongoing Approval Risk","sources":[{"url":"https://revoke.cash/exploits/dexible","name":"2023 Dexible Hack: Check If You're Affected — Revoke.cash","type":"research","credibility":2},{"url":"https://www.crunchbase.com/organization/dexible","name":"Dexible — Crunchbase Company Profile","type":"other","credibility":2}],"severity":"medium"},{"content":"Security researchers classified the vulnerability as an arbitrary external call vulnerability — a well-known smart contract attack vector. The precise flaw was the absence of an on-chain allowlist for router addresses in the selfSwap() function. The fill() function executed a delegatecall to an attacker-supplied address in routerData without any validation, effectively granting the attacker the ability to execute arbitrary calls in the context of the Dexible contract with access to all previously approved token allowances. The vulnerable contract address on Ethereum was identified as 0xde62e1b0edaa97e4ef25f0d140f1bf044d663091daf. Security firms BlockApex and SolidityScan both published post-incident analyses recommending router whitelisting, strict calldata validation, access control mechanisms, and mandatory professional audits as mitigations for this class of vulnerability.","heading":"Technical Analysis — Vulnerability Class","sources":[{"url":"https://blockapex.io/dexible-hack-analysis/","name":"Dexible Hack Analysis — BlockApex","type":"research","credibility":2},{"url":"https://blog.solidityscan.com/dexible-hack-analysis-never-blindly-trust-smart-contracts-c2aee7943c1a","name":"Dexible Hack Analysis — Never Blindly Trust Smart Contracts — SolidityScan","type":"research","credibility":2},{"url":"https://smartcontractshacking.com/hacks/dexible-v2-hack-2023","name":"Dexible V2 Hack (2023) — $2.0M Lost — Smart Contract Hacking","type":"research","credibility":2}],"severity":"critical"}],"timeline":[{"date":"2023-02-17","event":"Attacker (0x684083f312ac50f538cc4b634d85a2feafaab77a) exploits selfSwap vulnerability in Dexible V2 contracts, stealing approximately $2 million across Ethereum and Arbitrum from 17 user accounts.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2023/02/17/blocktower-capital-loses-15m-in-defi-market-aggregator-dexible-exploit-blockchain-data"},{"date":"2023-02-17","event":"PeckShield raises public alarm about the exploit on Twitter, approximately five hours before Dexible's official response.","source":"REKT News","source_url":"https://rekt.news/dexible-rekt"},{"date":"2023-02-17","event":"Dexible issues official announcement more than nine hours after the exploit began; CEO Michael Coon states contracts have been paused.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/dexibleapp-aggregator-hacked-for-2m-via-selfswap-function"},{"date":"2023-02-17","event":"Attacker converts stolen TRU tokens to ETH via SushiSwap and routes approximately $1.5 million through Tornado Cash on Ethereum; $450,000 from Arbitrum is bridged to BSC and also laundered via Tornado Cash.","source":"Quadriga Initiative","source_url":"https://quadrigainitiative.com/casestudy/dexibledexaggregatorselfswapexploit.php"},{"date":"2023-02-20","event":"Dexible team releases post-mortem report acknowledging no formal audit was performed on the v2 contracts and that internal review failed to identify the vulnerability.","source":"REKT News","source_url":"https://rekt.news/dexible-rekt"},{"date":"2023-02-20","event":"Security researchers publish technical analyses of the selfSwap arbitrary external call vulnerability, identifying the lack of router address validation as the root cause.","source":"BlockApex","source_url":"https://blockapex.io/dexible-hack-analysis/"},{"date":"2023-12-31","event":"Dexible listed as permanently closed on Crunchbase; no victim compensation program was ever established and stolen funds were not recovered.","source":"Crunchbase","source_url":"https://www.crunchbase.com/organization/dexible"}],"sources_used":[{"url":"https://rekt.news/dexible-rekt","name":"Dexible - REKT","type":"news_article","archive_url":"http://web.archive.org/web/20260313111040/https://rekt.news/dexible-rekt","credibility":2,"archive_timestamp":"2026-03-13T11:10:40+00:00"},{"url":"https://www.coindesk.com/tech/2023/02/17/blocktower-capital-loses-15m-in-defi-market-aggregator-dexible-exploit-blockchain-data","name":"BlockTower Capital Loses $1.5M in DeFi Market Aggregator Dexible Exploit — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260218125405/https://www.coindesk.com/tech/2023/02/17/blocktower-capital-loses-15m-in-defi-market-aggregator-dexible-exploit-blockchain-data","credibility":1,"archive_timestamp":"2026-02-18T12:54:05+00:00"},{"url":"https://cointelegraph.com/news/dexibleapp-aggregator-hacked-for-2m-via-selfswap-function","name":"Dexible aggregator hacked for $2M via 'selfSwap' function — CoinTelegraph","type":"news_article","archive_url":"http://web.archive.org/web/20250818161405/https://cointelegraph.com/news/dexibleapp-aggregator-hacked-for-2m-via-selfswap-function","credibility":1,"archive_timestamp":"2025-08-18T16:14:05+00:00"},{"url":"https://blockapex.io/dexible-hack-analysis/","name":"Dexible Hack Analysis — BlockApex","type":"research","archive_url":"http://web.archive.org/web/20260414001733/https://blockapex.io/dexible-hack-analysis/","credibility":2,"archive_timestamp":"2026-04-14T00:17:33+00:00"},{"url":"https://blog.solidityscan.com/dexible-hack-analysis-never-blindly-trust-smart-contracts-c2aee7943c1a","name":"Dexible Hack Analysis — Never Blindly Trust Smart Contracts — SolidityScan","type":"research","archive_url":"http://web.archive.org/web/20260724163254/https://blog.solidityscan.com/dexible-hack-analysis-never-blindly-trust-smart-contracts-c2aee7943c1a/","credibility":2,"archive_timestamp":"2026-07-24T16:32:54+00:00"},{"url":"https://revoke.cash/exploits/dexible","name":"2023 Dexible Hack: Check If You're Affected — Revoke.cash","type":"research","archive_url":"http://web.archive.org/web/20260520163459/https://revoke.cash/exploits/dexible","credibility":2,"archive_timestamp":"2026-05-20T16:34:59+00:00"},{"url":"https://quadrigainitiative.com/casestudy/dexibledexaggregatorselfswapexploit.php","name":"Feb 2023 - Dexible DEX Aggregator SelfSwap Exploit — Quadriga Initiative","type":"research","archive_url":"https://web.archive.org/web/20260724210636/https://quadrigainitiative.com/casestudy/dexibledexaggregatorselfswapexploit.php","credibility":2,"archive_timestamp":"2026-07-24T21:06:36+00:00"},{"url":"https://smartcontractshacking.com/hacks/dexible-v2-hack-2023","name":"Dexible V2 Hack (2023) — $2.0M Lost — Smart Contract Hacking","type":"research","archive_url":"http://web.archive.org/web/20260724211057/https://smartcontractshacking.com/hacks/dexible-v2-hack-2023","credibility":2,"archive_timestamp":"2026-07-24T21:10:57+00:00"},{"url":"https://www.crunchbase.com/organization/dexible","name":"Dexible — Crunchbase Company Profile","type":"other","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://home.treasury.gov/news/press-releases/jy0916","name":"U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash","type":"regulatory","archive_url":"http://web.archive.org/web/20260706154833/https://home.treasury.gov/news/press-releases/jy0916","credibility":1,"archive_timestamp":"2026-07-06T15:48:33+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:44.198917+00:00","updated_at":"2026-08-29T01:35:34.977+00:00"}}