{"investigation":{"slug":"monoswap","entity_name":"MonoSwap","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"MonoSwap is a decentralized exchange (DEX) and launchpad built on the Blast L2 network that launched in late February 2024. On July 24, 2024, the protocol was compromised via a social engineering attack in which a developer was tricked into installing infostealer malware disguised as a video conferencing app, allowing attackers to drain approximately $1.3 million in staked liquidity. The stolen funds were subsequently laundered through Tornado Cash, and the protocol has remained largely inactive with negligible TVL since the incident.","sections":[{"content":"On July 24, 2024, MonoSwap disclosed via its official X (Twitter) account that the protocol had been compromised. According to the team, one developer was contacted by individuals posing as venture capitalists seeking to discuss a potential investment in the project. During an arranged call, the developer was instructed to install an application named 'Kakao' — described as a video conferencing tool — which was in fact infostealer malware hosted at the domain kakaocall[.]kr. The malware extracted private keys from the developer's computer. Because that developer held administrative access to the protocol's wallets and smart contracts, the attackers gained full control and withdrew most staked liquidity positions from the platform. The team publicly confirmed: 'Yesterday, one of our developers installed a phishing app to join a call with scammers who posed as venture capitalists.' The attackers subsequently laundered approximately $1.3 million through the Tornado Cash cryptocurrency mixer. The protocol's TVL had peaked at roughly $2.8 million in April 2024 and had declined to approximately $1.5 million prior to the attack before being reduced to around $200,000 in its aftermath.","heading":"The July 2024 Hack","sources":[{"url":"https://www.web3isgoinggreat.com/?id=monoswap-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-monoswap-hack-july-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/breaking-monoswap-hacked-warning-issued-stay-away","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/monoswap-hack-staked-liquidity-stolen/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://crypto.news/monoswap-suffers-hack-urges-users-to-withdraw-funds/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Security firm SlowMist published an analysis identifying the malicious domain kakaocall[.]kr as the delivery mechanism for the infostealer malware. The domain redirected victims to additional infrastructure — including taxupay[.]com/process[.]php and a Dropbox-hosted executable disguised as KakaoCall software. SlowMist researchers found that kakaocall[.]kr shared identical code with a related domain, kakaocall[.]com, suggesting both operated under the same threat actor. The malware was found in connection with a phishing link promoted via a compromised tweet from the @OurTinTinLand account, which was used in an AMA event. The threat actor group demonstrated a pattern of constructing seemingly legitimate projects with fake websites, GitHub repositories, inflated engagement metrics, and published whitepapers in order to create the appearance of credibility before executing the social engineering portion of the attack. The central security failure identified by researchers was the concentration of control: a single developer held unrestricted access to all protocol wallets and smart contracts, eliminating any multi-signature safeguard.","heading":"Attack Vector: Social Engineering and Infostealer Malware","sources":[{"url":"https://slowmist.medium.com/cunning-phishing-in-the-dark-forest-493221c34687","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2024-07-25-monoswap-hack-involves-fake-kakao-video-software-11257487109529","name":"binance.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-monoswap-hack-july-2024","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT flagged the MonoSwap incident and observed that the attack methodology bore hallmarks associated with organized threat groups that have conducted similar social engineering operations across multiple DeFi protocols. The stolen funds were traced being laundered through Tornado Cash. The specific attribution of the MonoSwap hack to a named threat actor (such as Lazarus Group) was not conclusively established in public reporting at the time of this investigation; the Lazarus Group connection referenced in some secondary sources appears to derive from ZachXBT's concurrent analysis of the WazirX hack in the same period, not MonoSwap specifically.","heading":"ZachXBT Flag and Attribution","sources":[{"url":"https://www.web3isgoinggreat.com/?id=monoswap-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2024/07/monoswap-urges-users-to-withdraw-funds-after-major-hack","name":"cryptodaily.co.uk","type":"other","credibility":3}],"severity":"medium"},{"content":"MonoSwap launched on the Blast L2 mainnet in late February 2024, coinciding with Blast's mainnet launch. It operated as an automated market maker (AMM) DEX and launchpad, featuring token swapping, liquidity provision, yield farming, and a launchpad product. A key product was MUSD, described as an over-collateralized stablecoin-like token backed by Blast's native USDB stablecoin, with its value rebasing every eight hours. The protocol claimed to have processed over two million transactions from approximately 120,000 unique users during its testnet phase. The team was described as anonymous, with approximately 10 contributors, and reportedly included individuals with prior backgrounds at Gameloft and ONUS, based in Hanoi, Vietnam.","heading":"Protocol Background","sources":[{"url":"https://docs.monoswap.io/about/overview","name":"docs.monoswap.io","type":"other","credibility":3},{"url":"https://www.rootdata.com/Projects/detail/MonoSwap?k=MTEzMzM%3D","name":"rootdata.com","type":"other","credibility":3},{"url":"https://theblock101.com/what-is-monoswap-amm-dex-is-built-on-the-blast-ecosystem","name":"theblock101.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the July 2024 hack, MonoSwap issued an advisory urging all users to immediately withdraw staked positions and avoid adding further liquidity or staking in farming pools. The team stated it was 'planning the refund options' and would 'try its best to recover the hacked funds,' and indicated it was 'speaking with venture funders to resolve the issue and regain confidence.' No public evidence of a completed refund program or fund recovery has been identified in subsequent reporting. As of mid-2026, MonoSwap V3 (a Uniswap V3 fork on Blast) carries a TVL of approximately $95,000, indicating the protocol has not recovered meaningful user activity or liquidity following the incident. The original MonoSwap protocol on DefiLlama shows similarly negligible activity.","heading":"Post-Hack Status and Recovery","sources":[{"url":"https://defillama.com/protocol/monoswap-v3","name":"defillama.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/monoswap","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/07/25/monoswap-hack-users-advised-to-stop-staking-and-withdraw-funds/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=monoswap-hack","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers identified several structural weaknesses that contributed to the severity of the MonoSwap incident. The most significant was centralized key management: a single developer possessed unrestricted administrative access to all protocol wallets and smart contracts, negating the value of any distributed architecture. The protocol did not appear to have implemented multi-signature wallet controls or timelocks on privileged operations. The incident is consistent with a broader pattern of social engineering attacks targeting DeFi developers, in which attackers impersonate investors or partners to deliver malware via fraudulent meeting or productivity software. The counterfeit Kakao application used in this attack represented a specific variant of this threat pattern.","heading":"Security and Structural Risk Factors","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-monoswap-hack-july-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/cunning-phishing-in-the-dark-forest-493221c34687","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://blog.ueex.com/crypto-hacks/monoswap-hack/","name":"blog.ueex.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-02","event":"MonoSwap launches on Blast L2 mainnet coinciding with Blast's mainnet launch","source":"","date_original":"2024-02-01"},{"date":"2024-04","event":"MonoSwap TVL peaks at approximately $2.8 million","source":"","date_original":"2024-04-01"},{"date":"2024-07-23","event":"MonoSwap developer installs counterfeit Kakao video conferencing application (kakaocall[.]kr) during a call with individuals posing as venture capitalists; infostealer malware extracts private keys","source":""},{"date":"2024-07-24","event":"MonoSwap publicly discloses the hack via X (Twitter), advising users not to deposit funds or stake and to withdraw immediately; attackers drain most staked liquidity positions","source":""},{"date":"2024-07-25","event":"SlowMist publishes analysis of kakaocall[.]kr phishing infrastructure; links it to broader coordinated social engineering campaign; same phishing domain found in compromised @OurTinTinLand tweet","source":""},{"date":"2024-07-25","event":"Multiple security outlets confirm approximately $1.3 million in losses laundered through Tornado Cash","source":""},{"date":"2024-07-25","event":"MonoSwap states it is investigating and 'planning refund options'","source":""},{"date":"2026-05","event":"MonoSwap V3 TVL remains at approximately $95,000; no evidence of refund program or recovery; protocol effectively dormant","source":"","date_original":"2026-05-01"}],"sources_used":[{"url":"https://www.web3isgoinggreat.com/?id=monoswap-hack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260413103615/https://www.web3isgoinggreat.com/?id=monoswap-hack","credibility":3,"archive_timestamp":"2026-04-13T10:36:15+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-monoswap-hack-july-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260415073840/https://www.halborn.com/blog/post/explained-the-monoswap-hack-july-2024","credibility":3,"archive_timestamp":"2026-04-15T07:38:40+00:00"},{"url":"https://cointelegraph.com/news/breaking-monoswap-hacked-warning-issued-stay-away","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830040816/https://cointelegraph.com/news/breaking-monoswap-hacked-warning-issued-stay-away","credibility":3,"archive_timestamp":"2026-08-30T04:08:16+00:00"},{"url":"https://cryptobriefing.com/monoswap-hack-staked-liquidity-stolen/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260114161630/https://cryptobriefing.com/monoswap-hack-staked-liquidity-stolen/","credibility":3,"archive_timestamp":"2026-01-14T16:16:30+00:00"},{"url":"https://crypto.news/monoswap-suffers-hack-urges-users-to-withdraw-funds/","name":"crypto.news","type":"other","archive_url":"https://web.archive.org/web/20260829131450/https://crypto.news/monoswap-suffers-hack-urges-users-to-withdraw-funds/","credibility":3,"archive_timestamp":"2026-08-29T13:14:50+00:00"},{"url":"https://slowmist.medium.com/cunning-phishing-in-the-dark-forest-493221c34687","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260303135802/https://slowmist.medium.com/cunning-phishing-in-the-dark-forest-493221c34687","credibility":3,"archive_timestamp":"2026-03-03T13:58:02+00:00"},{"url":"https://www.binance.com/en/square/post/2024-07-25-monoswap-hack-involves-fake-kakao-video-software-11257487109529","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260829184957/https://www.binance.com/en/square/post/2024-07-25-monoswap-hack-involves-fake-kakao-video-software-11257487109529","credibility":3,"archive_timestamp":"2026-08-29T18:49:57+00:00"},{"url":"https://cryptodaily.co.uk/2024/07/monoswap-urges-users-to-withdraw-funds-after-major-hack","name":"cryptodaily.co.uk","type":"other","archive_url":"http://web.archive.org/web/20250908023614/https://cryptodaily.co.uk/2024/07/monoswap-urges-users-to-withdraw-funds-after-major-hack","credibility":3,"archive_timestamp":"2025-09-08T02:36:14+00:00"},{"url":"https://docs.monoswap.io/about/overview","name":"docs.monoswap.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.rootdata.com/Projects/detail/MonoSwap?k=MTEzMzM%3D","name":"rootdata.com","type":"other","archive_url":"https://web.archive.org/web/20260829153109/https://www.rootdata.com/Projects/detail/MonoSwap?k=MTEzMzM%3D","credibility":3,"archive_timestamp":"2026-08-29T15:31:09+00:00"},{"url":"https://theblock101.com/what-is-monoswap-amm-dex-is-built-on-the-blast-ecosystem","name":"theblock101.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/monoswap-v3","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250917111028/https://defillama.com/protocol/monoswap-v3","credibility":3,"archive_timestamp":"2025-09-17T11:10:28+00:00"},{"url":"https://defillama.com/protocol/monoswap","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20251007113604/https://defillama.com/protocol/monoswap","credibility":3,"archive_timestamp":"2025-10-07T11:36:04+00:00"},{"url":"https://www.cryptotimes.io/2024/07/25/monoswap-hack-users-advised-to-stop-staking-and-withdraw-funds/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260829151229/https://www.cryptotimes.io/2024/07/25/monoswap-hack-users-advised-to-stop-staking-and-withdraw-funds/","credibility":3,"archive_timestamp":"2026-08-29T15:12:29+00:00"},{"url":"https://blog.ueex.com/crypto-hacks/monoswap-hack/","name":"blog.ueex.com","type":"other","archive_url":"https://web.archive.org/web/20260829124814/https://blog.ueex.com/crypto-hacks/monoswap-hack/","credibility":3,"archive_timestamp":"2026-08-29T12:48:14+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:30.488385+00:00","updated_at":"2026-08-30T05:14:07.100092+00:00"}}