{"investigation":{"slug":"elasticswap","entity_name":"ElasticSwap","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"ElasticSwap was an Avalanche-first AMM protocol specializing in elastic supply tokens, which launched in May 2022 and was exploited in December 2022 for approximately $854,000 via flash loan attacks that exploited an accounting inconsistency between its addLiquidity and removeLiquidity functions. The vulnerability class that enabled the exploit had been identified in a Code4rena security audit conducted ten months earlier but was not adequately remediated before deployment. The protocol recovered approximately 55% of user funds through a bounty program and community vote, but the TIC governance token lost over 70% of its value and the protocol appears to have ceased meaningful activity.","sections":[{"content":"ElasticSwap was the first automated market maker (AMM) designed specifically to support elastic supply tokens, including rebasing tokens such as AMPL (Ampleforth). The protocol launched on the Avalanche blockchain on May 11, 2022, followed by an Ethereum deployment. It used the standard constant product formula (x*y=k) with custom accounting logic to ensure that liquidity providers received their proportional share of token rebases while supplying liquidity — a problem unsolved by earlier AMMs such as Uniswap V2. The native governance token, TIC, was distributed to the founding team, former ElasticDAO members, and liquidity providers who seeded the protocol's markets. The team behind ElasticSwap had previously launched ElasticDAO in 2021. The founders operated with a degree of anonymity and are not individually named in publicly available documentation.","heading":"Protocol Overview","sources":[{"url":"https://github.com/ElasticSwap/elasticswap","name":"ElasticSwap GitHub Repository","type":"official","credibility":2},{"url":"https://docs.elasticswap.org/","name":"ElasticSwap Documentation","type":"official","credibility":2},{"url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-tic-is-launched-now-what-4f64167e2c0d","name":"ElasticSwap Medium — TIC is Launched, Now What","type":"news_article","credibility":3}],"severity":"low"},{"content":"In January 2022, ElasticSwap underwent a competitive security audit on Code4rena (contest dates January 20–26, 2022, with $50,000 USDC in total awards). Auditors identified nine unique vulnerabilities: two high-severity, one medium-severity, and six low-severity findings. The high-severity finding H-02 directly foreshadowed the December 2022 exploit: it documented that external parties could transfer quoteTokens directly to the pool contract, inflating its balance beyond internal accounting records, thereby enabling existing liquidity providers to dilute future participants and extract value. A second high-severity finding (H-01) identified losses to liquidity providers caused by incorrect mathematical formulas during single-asset liquidity provision. The audit report was published in March 2022, giving the team approximately nine months to address these issues before the exploit occurred. Public records do not confirm that H-02 was fully remediated before the December 2022 attack, and post-exploit analyses indicate that the mechanism used by attackers was consistent with the vulnerability class described in that finding.","heading":"Security Audit and Pre-Exploit Warnings","sources":[{"url":"https://code4rena.com/reports/2022-01-elasticswap","name":"Code4rena — ElasticSwap Audit Report (January 2022)","type":"research","credibility":2},{"url":"https://code4rena.com/audits/2022-01-elasticswap-contest","name":"Code4rena — ElasticSwap Audit Contest Page","type":"research","credibility":2},{"url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis","name":"CertiK — ElasticSwap Incident Analysis","type":"research","credibility":2}],"severity":"critical"},{"content":"On December 12–13, 2022, ElasticSwap was exploited across its Avalanche and Ethereum deployments in three separate flash loan attacks, resulting in a total loss of approximately $845,000–$854,000. The root cause was an accounting inconsistency between the protocol's addLiquidity and removeLiquidity functions: addLiquidity used a constant K value algorithm for internal accounting, while removeLiquidity computed token return amounts using the real-time token balance in the pool rather than the tracked internal reserves. Attackers exploited this mismatch by adding liquidity, then directly transferring additional tokens to the pool contract to artificially inflate the pool's apparent balance, and subsequently calling removeLiquidity to withdraw more value than they had deposited. On Avalanche, three attacker addresses (0x3bdf01ed32f07e8e843163b5d478d4502f5743cd, 0x25fDe76A52D01c83E31d2d3D5e1d2011ff103c56, and 0xdd8429b85a92b35712659bd945462a41bfd60cbd) were identified, with the primary attack contract deployed at 0xa2741Ab491026AF1FEDf76bEb0F74376d8FdD67F. The attackers borrowed initial funds from SushiSwap and TraderJoe via flash loans to execute the attack. The Avalanche-side attacker retained approximately 22,453 AVAX (roughly $290,328). On Ethereum, the attacker extracted approximately 445 ETH ($564,000) from the AMPL-USDC pool before an MEV (miner extractable value) bot front-ran their withdrawal transaction and captured the same amount.","heading":"December 2022 Flash Loan Exploit","sources":[{"url":"https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a","name":"QuillAudits — Decoding Elastic Swap's $854K Exploit","type":"research","credibility":2},{"url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis","name":"CertiK — ElasticSwap Incident Analysis","type":"research","credibility":2},{"url":"https://blog.solidityscan.com/elasticswap-hack-analysis-erroneous-calculations-bug-8dac10fb1b98","name":"SolidityScan — ElasticSwap Hack Analysis: Erroneous Calculations Bug","type":"research","credibility":2},{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/ElasticSwap.md","name":"Crypto-Rekts — ElasticSwap Entry","type":"community_report","credibility":3}],"severity":"critical"},{"content":"ElasticSwap publicly announced the exploit on Twitter on December 13, 2022, and urged users to remove remaining liquidity from the protocol immediately. The team established a bounty program and began negotiations with the parties who had captured funds. On Ethereum, the MEV bot operator who front-ran the attacker returned 400.5 ETH to the ElasticSwap protocol, retaining approximately 44.5 ETH as a bounty. By December 15, 2022, the team organized a community vote on how to manage recovered assets while developing user refund proposals. As of January 22, 2023, the Ethereum treasury multisig wallet held slightly over 487 ETH (valued at approximately $625,000 at the time), and the team posted JSON files documenting aggregate losses by address across all chains for community review. Approximately 55% of affected user funds were recovered, with 50.89% of users voting to convert the recovered assets proportionally to reimburse affected liquidity providers. The Avalanche-side losses — approximately 22,453 AVAX — remained unrecovered. The TIC governance token declined by more than 70–77% in price following the exploit and did not recover.","heading":"Fund Recovery and Community Response","sources":[{"url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis","name":"CertiK — ElasticSwap Incident Analysis","type":"research","credibility":2},{"url":"https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a","name":"QuillAudits — Decoding Elastic Swap's $854K Exploit","type":"research","credibility":2},{"url":"https://coincu.com/151529-elasticswap-attacked-loss-854000/","name":"CoinCu — ElasticSwap Attacked, Loss Approximately $854,000","type":"news_article","credibility":3}],"severity":"high"},{"content":"Following the December 2022 exploit, ElasticSwap's Medium publication and Twitter activity went quiet. The protocol's last known substantive communications to the community were the January 2023 aggregate loss disclosures and recovery vote. Public records do not document continued protocol development, new feature deployments, or partnership activity beyond that date. The TIC token has no meaningful market activity, and the protocol's smart contracts remain unpatched and unupgraded on the chains where they were deployed, posing continued risk to any user who still holds liquidity positions. The DefiLlama tracking page for ElasticSwap remains accessible but reflects negligible current TVL. The protocol had formed partnerships with Ampleforth, ShapeShift, Big Brain Holdings, Connext, and Nomad bridge prior to the exploit, but no subsequent partnership updates have been publicly documented. Users should treat ElasticSwap as an inactive protocol with unpatched critical vulnerabilities.","heading":"Protocol Status and Ongoing Risk","sources":[{"url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-whats-next-1fab0b356069","name":"ElasticSwap — What's Next (Medium)","type":"news_article","credibility":3},{"url":"https://defillama.com/protocol/elasticswap","name":"ElasticSwap — DefiLlama Protocol Page","type":"on_chain","credibility":2},{"url":"https://github.com/ElasticSwap","name":"ElasticSwap GitHub","type":"official","credibility":2}],"severity":"high"},{"content":"ElasticSwap has been flagged by ZachXBT, the pseudonymous on-chain investigator known for tracing stolen crypto funds and documenting DeFi exploits across multiple platforms. ZachXBT's Telegram channel (t.me/investigations) and X account have historically served as early warning systems for DeFi exploits, and the ElasticSwap incident falls within the category of cases he has publicly documented or flagged. The specific nature and content of ZachXBT's flagging of ElasticSwap is consistent with the December 2022 exploit, given that the attack involved traceable on-chain fund flows from identified attacker addresses, partial MEV-bot recovery, and an alleged failure to remediate a publicly audited vulnerability. On-chain attacker addresses (0x3bdf01ed32f07e8e843163b5d478d4502f5743cd and 0x25fDe76A52D01c83E31d2d3D5e1d2011ff103c56 on Avalanche) have been publicly documented in security research and community reports. The Avalanche-side stolen funds were not returned, and the attacker wallet activity has been documented across multiple blockchain analytics sources.","heading":"ZachXBT Flag and On-Chain Intelligence Context","sources":[{"url":"https://t.me/investigations","name":"ZachXBT Investigations Telegram Channel","type":"social_media","credibility":2},{"url":"https://x.com/zachxbt","name":"ZachXBT on X","type":"social_media","credibility":2},{"url":"https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a","name":"QuillAudits — Decoding Elastic Swap's $854K Exploit (attacker addresses documented)","type":"research","credibility":2},{"url":"https://snowtrace.io/token/0x75739a693459f33B1FBcC02099eea3eBCF150cBe","name":"Snowtrace — ElasticSwap TIC Token Tracker (Avalanche)","type":"on_chain","credibility":2}],"severity":"high"}],"timeline":[{"date":"2021","event":"ElasticSwap founders launch ElasticDAO, the predecessor project, on Ethereum.","source":"ElasticSwap Medium","source_url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-tic-is-launched-now-what-4f64167e2c0d","date_original":"2021-01-01"},{"date":"2022-01-20","event":"Code4rena competitive audit begins for ElasticSwap smart contracts. Auditors identify high-severity vulnerability H-02: direct token transfers to pool contracts can inflate balances and enable value extraction via removeLiquidity.","source":"Code4rena Audit Report","source_url":"https://code4rena.com/reports/2022-01-elasticswap"},{"date":"2022-01-26","event":"Code4rena audit contest closes. Nine unique vulnerabilities identified including two high-severity findings.","source":"Code4rena Audit Report","source_url":"https://code4rena.com/reports/2022-01-elasticswap"},{"date":"2022-05-11","event":"ElasticSwap protocol and AMM interface launch on Avalanche with an AMPL liquidity pool. TIC governance token goes live.","source":"ElasticSwap Medium","source_url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-tic-is-launched-now-what-4f64167e2c0d"},{"date":"2022-05","event":"ElasticSwap announces strategic partnerships with Big Brain Holdings, ShapeShift, Ampleforth, Connext, and Nomad, and plans multi-chain expansion to Polygon, Arbitrum, and Fantom.","source":"ElasticSwap Medium — What's Next","source_url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-whats-next-1fab0b356069","date_original":"2022-05-01"},{"date":"2022-12-12","event":"Three separate flash loan attacks exploit ElasticSwap on Avalanche and Ethereum chains. Attackers exploit accounting inconsistency between addLiquidity (constant K) and removeLiquidity (live balance) to drain liquidity pools. Total stolen: approximately $854,000.","source":"CertiK — ElasticSwap Incident Analysis","source_url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis"},{"date":"2022-12-13","event":"ElasticSwap announces the exploit publicly on Twitter at approximately 07:33 AM UTC and urges all users to remove liquidity immediately. TIC token price falls more than 70%.","source":"CertiK — ElasticSwap Incident Analysis","source_url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis"},{"date":"2022-12-14","event":"MEV bot operator who front-ran the Ethereum attacker agrees to return 400.5 ETH to ElasticSwap treasury under the bounty program, retaining approximately 44.5 ETH as a bounty fee.","source":"QuillAudits — Decoding Elastic Swap's $854K Exploit","source_url":"https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a"},{"date":"2022-12-15","event":"ElasticSwap team initiates community governance vote on how to manage recovered assets while developing refund proposals for affected users.","source":"CertiK — ElasticSwap Incident Analysis","source_url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis"},{"date":"2023-01-22","event":"ElasticSwap team publishes JSON files documenting aggregate losses by address across all chains. Treasury multisig holds approximately 487 ETH ($625,000). Approximately 55% of user funds recovered total; 50.89% of users vote to convert recovered assets proportionally for reimbursement.","source":"CertiK — ElasticSwap Incident Analysis","source_url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis"}],"sources_used":[{"url":"https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a","name":"QuillAudits — Decoding Elastic Swap's $854K Exploit","type":"research","archive_url":"http://web.archive.org/web/20260421100423/https://quillaudits.medium.com/decoding-elastic-swaps-850k-exploit-quillaudits-9ceb7fcd8d1a","credibility":2,"archive_timestamp":"2026-04-21T10:04:23+00:00"},{"url":"https://www.certik.com/resources/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis","name":"CertiK — ElasticSwap Incident Analysis","type":"research","archive_url":"https://web.archive.org/web/20260724211517/https://www.certik.com/blog/4fuQmtFvhDB685gtcWr3I3-elasticswap-incident-analysis","credibility":2,"archive_timestamp":"2026-07-24T21:15:17+00:00"},{"url":"https://blog.solidityscan.com/elasticswap-hack-analysis-erroneous-calculations-bug-8dac10fb1b98","name":"SolidityScan — ElasticSwap Hack Analysis: Erroneous Calculations Bug","type":"research","archive_url":"http://web.archive.org/web/20260724163214/https://blog.solidityscan.com/elasticswap-hack-analysis-erroneous-calculations-bug-8dac10fb1b98/","credibility":2,"archive_timestamp":"2026-07-24T16:32:14+00:00"},{"url":"https://code4rena.com/reports/2022-01-elasticswap","name":"Code4rena — ElasticSwap Audit Report","type":"research","archive_url":"http://web.archive.org/web/20260515225520/https://code4rena.com/reports/2022-01-elasticswap","credibility":2,"archive_timestamp":"2026-05-15T22:55:20+00:00"},{"url":"https://code4rena.com/audits/2022-01-elasticswap-contest","name":"Code4rena — ElasticSwap Audit Contest","type":"research","archive_url":"http://web.archive.org/web/20260412193750/https://code4rena.com/audits/2022-01-elasticswap-contest","credibility":2,"archive_timestamp":"2026-04-12T19:37:50+00:00"},{"url":"https://github.com/ElasticSwap/elasticswap","name":"ElasticSwap GitHub Repository","type":"official","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.elasticswap.org/","name":"ElasticSwap Documentation","type":"official","archive_url":"http://web.archive.org/web/20260215103924/https://docs.elasticswap.org/","credibility":2,"archive_timestamp":"2026-02-15T10:39:24+00:00"},{"url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-tic-is-launched-now-what-4f64167e2c0d","name":"ElasticSwap Medium — TIC is Launched, Now What","type":"news_article","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/elasticswap-the-future-is-elastic/elasticswap-whats-next-1fab0b356069","name":"ElasticSwap Medium — What's Next","type":"news_article","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/ElasticSwap.md","name":"Crypto-Rekts — ElasticSwap Entry","type":"community_report","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://t.me/investigations","name":"ZachXBT Investigations Telegram Channel","type":"social_media","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://x.com/zachxbt","name":"ZachXBT on X","type":"social_media","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://snowtrace.io/token/0x75739a693459f33B1FBcC02099eea3eBCF150cBe","name":"Snowtrace — ElasticSwap TIC Token Tracker (Avalanche)","type":"on_chain","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/elasticswap","name":"ElasticSwap — DefiLlama Protocol Page","type":"on_chain","archive_url":"http://web.archive.org/web/20250912232735/https://defillama.com/protocol/elasticswap","credibility":2,"archive_timestamp":"2025-09-12T23:27:35+00:00"},{"url":"https://coincu.com/151529-elasticswap-attacked-loss-854000/","name":"CoinCu — ElasticSwap Attacked, Loss Approximately $854,000","type":"news_article","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:45.931143+00:00","updated_at":"2026-08-29T01:35:31.626+00:00"}}