{"investigation":{"slug":"saddle-finance","entity_name":"Saddle Finance","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Saddle Finance was an Ethereum-based automated market maker (AMM) optimized for pegged-value assets such as stablecoins and wrapped BTC, founded in 2020 and launched in January 2021. The protocol suffered a critical exploit on April 30, 2022, when an attacker leveraged an unpatched MetaSwapUtils library bug to drain approximately $11 million via flash-loan-assisted price manipulation, with $3.8 million subsequently rescued by security firm BlockSec. The protocol formally wound down in September 2023 following a DAO vote (SIP-54) triggered in part by the broader DeFi security climate after the Curve Finance hack.","sections":[{"content":"Saddle Finance was founded in 2020 by Sunil Srivatsa, with a team of engineers drawing from prior experience at web2 companies including Uber, Amazon, and Square. The protocol launched on Ethereum mainnet on January 19, 2021, positioning itself as a low-slippage AMM for pegged-value crypto assets, adopting Curve Finance's StableSwap invariant algorithm ported into Solidity. At launch, Saddle raised a $4.3 million seed round from Coinbase Ventures, Electric Capital, Framework Ventures, Polychain Capital, Alameda Research, Divergence Ventures, and Dragonfly Capital. A subsequent $7.5 million Series A round closed in November 2021, led by Electric Capital, bringing total venture funding to approximately $11.8 million. Saddle supported base pools and metapools across Ethereum, Arbitrum, Optimism, Fantom, and Evmos, covering stablecoin pairs (USDT, USDC, DAI, FRAX) and wrapped BTC. The protocol's SDL governance token was issued and a veSDL vote-escrow system was implemented. At its peak, Saddle held hundreds of millions in total value locked (TVL). Shortly after launch, Curve Finance publicly accused Saddle of copying its algorithm; a Quantstamp audit report had noted the Saddle implementation was ported directly from Curve's contracts. The dispute did not result in formal legal action but drew attention to intellectual property norms in open-source DeFi. Saddle had received security audits from Certik (October 2020), Quantstamp (December 2020 and March 2021), and OpenZeppelin (December 2020); admin keys were secured by a 3-of-8 Gnosis Safe multisig with well-known DeFi community signers.","heading":"Background","sources":[{"url":"https://www.coindesk.com/business/2021/01/19/saddle-raises-43m-for-slippage-free-defi-trading","name":"","type":"other","credibility":3},{"url":"https://www.globenewswire.com/news-release/2021/11/11/2332775/0/en/Saddle-Raises-7-5-Million-in-Funding-Round-From-Polychain-and-Electric-Capital-to-Expand-Automated-Market-Maker-Capabilities.html","name":"","type":"other","credibility":3},{"url":"https://blog.openzeppelin.com/saddle-contracts-audit/","name":"","type":"other","credibility":3},{"url":"https://docs.saddle.finance/smart-contract-audit","name":"","type":"other","credibility":3},{"url":"https://cryptobriefing.com/curve-accuses-saddle-finance-of-copying-its-code/","name":"","type":"other","credibility":3},{"url":"https://medium.com/saddle/introducing-saddle-a-specialized-amm-for-pegged-value-crypto-assets-e607d2747345","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 30, 2022, Saddle Finance suffered a critical exploit across three attack transactions that drained approximately $11 million from the sUSD-saddleUSD-V2 metapool. The root cause was a known bug in an outdated version of the MetaSwapUtils library that failed to use a VirtualPrice when computing the value of LP tokens during metapool swaps. Saddle had identified this issue as early as November 2021 after forks of its code (including Nerve Finance and Synapse Protocol) were exploited using the same class of vulnerability. Saddle deployed a patched MetaSwapUtils library in December 2021, but the corrected code was never integrated into the existing sUSD metapool swap pathway, leaving the vulnerable version active. The attacker (address 0x63341ba917de90498f3903b199df5699b4a55ac0, funded via Tornado Cash) executed a flash loan of approximately $15 million USDC from Euler Finance, swapped USDC for sUSD via Curve, then exploited the mispriced LP token calculation by repeatedly swapping sUSD for saddleUSD-V2 LP tokens and reversing the swap, extracting excess sUSD on each cycle. Two successful attacker transactions were executed: TX1 (0x2b023d65485c4bb68d781960c2196588d03b871dc9eb1c054f596b7ca6f7da56) yielding approximately 3,375 ETH, and TX2 (0xe7e0474793aad11875c131ebd7582c8b73499dd3c5a473b59e6762d4e373d7b8) yielding approximately 557 ETH. A third attack attempt (0xd9bc83688e8eddde39bd9073c363665b1419d475dd4498e81b52cce41d7c76b3) was blocked by BlockSec's intervention. The total gross loss before recovery was approximately 3,932 ETH, worth roughly $11 million at the time. The same weekend, Rari Capital and Fei Protocol were exploited for approximately $80 million through a separate reentrancy vulnerability, concentrating negative attention on the DeFi sector. An earlier, less severe incident occurred on Saddle's launch day in January 2021, when arbitrageurs extracted approximately 7.9 BTC (~$275,000) from newly seeded liquidity pools by exploiting price imbalances within six minutes of launch. A Quantstamp audit contemporaneously noted the team's difficulty in fully understanding the ported Curve code, a warning that presaged the 2022 failure.","heading":"The Exploit","sources":[{"url":"https://medium.com/immunefi/hack-analysis-saddle-finance-april-2022-f2bcb119f38","name":"","type":"other","credibility":3},{"url":"https://rekt.news/saddle-finance-rekt2","name":"","type":"other","credibility":3},{"url":"https://therecord.media/hackers-steal-90-million-from-defi-platforms-rari-capital-and-saddle-finance","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/144491/stablecoin-dex-saddle-finance-hacked-for-10-million","name":"","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/saddle-finance-loses-more-than-11-million-to-hack","name":"","type":"other","credibility":3},{"url":"https://rekt.news/saddle-finance-rekt","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker address 0x63341ba917de90498f3903b199df5699b4a55ac0 was funded with 1 ETH withdrawn from Tornado Cash prior to the attack, a common obfuscation technique used in DeFi exploits. The two confirmed exploit transactions are: 0x2b023d65485c4bb68d781960c2196588d03b871dc9eb1c054f596b7ca6f7da56 (primary, approximately 3,375 ETH extracted) and 0xe7e0474793aad11875c131ebd7582c8b73499dd3c5a473b59e6762d4e373d7b8 (secondary, approximately 557 ETH extracted). Following the exploit, post-incident reports indicate the attacker routed approximately 900 ETH into Tornado Cash while the majority of stolen funds initially remained at the exploiter address. BlockSec's intervention (rescue transaction 0x9549c0cb48ec5a5a2c4703cbbbbea5638028b2d8c8adc103220ef1c7fe5e99a3) was executed at block 14684434, two blocks after detecting the failed third attack attempt at block 14684432. BlockSec secured 1,360 ETH (approximately $3.8 million) through this protective transaction, which used Flashbots to ensure block priority. The vulnerable function in the attack sequence was identified as 0xaf8271f7, associated with the MetaSwapUtils metapool swap pathway that bypassed the December 2021 VirtualPrice fix.","heading":"On-Chain Evidence","sources":[{"url":"https://blocksec.com/blog/blocked-saddle-finance-attack-industry-s-first-influential-blocking-to-rescue-3-800-000","name":"","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-saddle-finance-april-2022-f2bcb119f38","name":"","type":"other","credibility":3},{"url":"https://rekt.news/saddle-finance-rekt2","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 30, 2022 exploit, BlockSec's automated detection system identified the attack pattern and successfully executed a rescue transaction that recovered approximately 1,360 ETH ($3.8 million), representing roughly 34% of the total amount drained. This was publicly described by BlockSec as an industry-first \"influential blocking\" intervention using its Phalcon monitoring system and Flashbots bundle submission. Saddle Finance did not announce a user compensation plan or protocol treasury reimbursement for the remaining approximately $7.2 million net loss sustained by liquidity providers. The Saddle team did pause the affected metapool swaps promptly after being alerted. The protocol continued operating in a diminished capacity after the hack; by August 2023, its TVL had fallen to approximately $2 million. The formal wind-down was initiated on August 8, 2023, when founder Sunil Srivatsa submitted SIP-54 to the Saddle DAO, proposing to pause all pools, dissolve the community multisig, and distribute the DAO treasury (primarily 1.545 million ARB tokens received from the Arbitrum airdrop) to SDL and veSDL token holders, with veSDL holders receiving a four-times larger proportional allocation. Srivatsa cited the July 2023 Curve Finance exploit as a reminder of the persistent threat of smart contract bugs. The Saddle DAO voted to approve SIP-54, and protocol developers stepped back from the project by September 30, 2023.","heading":"Recovery","sources":[{"url":"https://blocksec.com/blog/blocked-saddle-finance-attack-industry-s-first-influential-blocking-to-rescue-3-800-000","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/venture-backed-saddle-finance-proposes-203900725.html","name":"","type":"other","credibility":3},{"url":"https://blofin.com/news/saddle-finance-plans-to-wind-down-airdrop-arb-to-sdl-and-vesdl-holders","name":"","type":"other","credibility":3},{"url":"https://bsc.news/post/saddle-finance-decides-to-wind-down-distributes-treasury-to-holders","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Saddle Finance represents a protocol that is no longer active, having formally wound down in September 2023. The primary risk indicators for the protocol's history include: (1) a critical smart contract vulnerability that was identified via fork exploits in November 2021, partially patched in December 2021, but not correctly applied to all deployed pools, resulting in an $11 million loss in April 2022; (2) a launch-day arbitrage incident in January 2021 that drained approximately $275,000 from early liquidity providers, with the team's response placing responsibility on users rather than addressing protocol design; (3) Curve Finance's public accusation of code copying without attribution, highlighting questions about the development team's deep understanding of the ported algorithm — an assessment reinforced by the Quantstamp auditors; (4) failure to provide confirmed user restitution for the April 2022 exploit losses despite having received over $11.8 million in venture funding; and (5) a wind-down that distributed treasury assets primarily via an ARB airdrop valued at fractions of a cent per SDL token, offering minimal recovery value to SDL holders. No regulatory actions (SEC, CFTC, DOJ) have been identified against Saddle Finance or its founders. The protocol is shut down and pools are paused. Any remaining user funds in Saddle contracts should be considered at risk given the absence of active development and maintenance.","heading":"Risk Assessment","sources":[{"url":"https://medium.com/immunefi/hack-analysis-saddle-finance-april-2022-f2bcb119f38","name":"","type":"other","credibility":3},{"url":"https://rekt.news/saddle-finance-rekt2","name":"","type":"other","credibility":3},{"url":"https://rekt.news/saddle-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/venture-backed-saddle-finance-proposes-203900725.html","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-exploits-continue-to-plague-industry-as-saddle-finance-hack-sees-10m-stolen/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-01-19","event":"Saddle Finance launches on Ethereum mainnet and simultaneously closes $4.3 million seed round from Coinbase Ventures, Electric Capital, Polychain Capital, Alameda Research, and others.","source":""},{"date":"2021-01-19","event":"Within six minutes of launch, three arbitrageurs extract approximately 7.9 BTC (~$275,000) from newly seeded pools by exploiting price imbalances; team response places responsibility on users.","source":""},{"date":"2021-01-20","event":"Curve Finance publicly accuses Saddle Finance of copying its StableSwap algorithm without attribution, citing a Quantstamp audit finding that Saddle's code was ported directly from Curve's contracts.","source":""},{"date":"2021-11-11","event":"Saddle raises $7.5 million Series A round led by Electric Capital, bringing total funding to approximately $11.8 million.","source":""},{"date":"2021-11","event":"Forks of Saddle's code (Nerve Finance, Synapse Protocol) are exploited using the MetaSwapUtils VirtualPrice pricing bug, alerting the Saddle team to the vulnerability class.","source":"","date_original":"2021-11-01"},{"date":"2021-12","event":"Saddle deploys a patched MetaSwapUtils library addressing the VirtualPrice LP token calculation bug, but fails to migrate existing sUSD metapool to use the corrected code.","source":"","date_original":"2021-12-01"},{"date":"2022-04-30","event":"Attacker (0x63341ba917de90498f3903b199df5699b4a55ac0, funded via Tornado Cash) drains approximately 3,932 ETH (~$11 million) from the sUSD-saddleUSD-V2 metapool across two successful flash-loan exploit transactions.","source":""},{"date":"2022-04-30","event":"BlockSec detects the exploit in real time and executes rescue transaction 0x9549c0cb... at block 14684434, recovering approximately 1,360 ETH ($3.8 million) from a blocked third attack attempt.","source":""},{"date":"2022-04-30","event":"Rari Capital and Fei Protocol suffer a separate $80 million reentrancy exploit on the same day, compounding DeFi sector stress.","source":""},{"date":"2023-08-08","event":"Founder Sunil Srivatsa submits SIP-54 to Saddle DAO proposing protocol wind-down by September 30, 2023, citing the Curve Finance hack as a renewed reminder of smart contract risk.","source":""},{"date":"2023-09-30","event":"Saddle Finance formally shuts down; all pools paused, community multisig dissolved, DAO treasury distributed to SDL and veSDL token holders as ARB airdrop.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2021/01/19/saddle-raises-43m-for-slippage-free-defi-trading","name":"","type":"other","archive_url":"http://web.archive.org/web/20251117232347/https://www.coindesk.com/business/2021/01/19/saddle-raises-43m-for-slippage-free-defi-trading","credibility":3,"archive_timestamp":"2025-11-17T23:23:47+00:00"},{"url":"https://www.globenewswire.com/news-release/2021/11/11/2332775/0/en/Saddle-Raises-7-5-Million-in-Funding-Round-From-Polychain-and-Electric-Capital-to-Expand-Automated-Market-Maker-Capabilities.html","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830005217/https://www.globenewswire.com/news-release/2021/11/11/2332775/0/en/Saddle-Raises-7-5-Million-in-Funding-Round-From-Polychain-and-Electric-Capital-to-Expand-Automated-Market-Maker-Capabilities.html","credibility":3,"archive_timestamp":"2026-08-30T00:52:17+00:00"},{"url":"https://blog.openzeppelin.com/saddle-contracts-audit/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://docs.saddle.finance/smart-contract-audit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511033308/https://docs.saddle.finance/smart-contract-audit","credibility":3,"archive_timestamp":"2026-05-11T03:33:08+00:00"},{"url":"https://cryptobriefing.com/curve-accuses-saddle-finance-of-copying-its-code/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260116211747/https://cryptobriefing.com/curve-accuses-saddle-finance-of-copying-its-code/","credibility":3,"archive_timestamp":"2026-01-16T21:17:47+00:00"},{"url":"https://medium.com/saddle/introducing-saddle-a-specialized-amm-for-pegged-value-crypto-assets-e607d2747345","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/immunefi/hack-analysis-saddle-finance-april-2022-f2bcb119f38","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://rekt.news/saddle-finance-rekt2","name":"","type":"other","archive_url":"http://web.archive.org/web/20260415163741/https://rekt.news/saddle-finance-rekt2","credibility":3,"archive_timestamp":"2026-04-15T16:37:41+00:00"},{"url":"https://therecord.media/hackers-steal-90-million-from-defi-platforms-rari-capital-and-saddle-finance","name":"","type":"other","archive_url":"http://web.archive.org/web/20251029055555/https://therecord.media/hackers-steal-90-million-from-defi-platforms-rari-capital-and-saddle-finance","credibility":3,"archive_timestamp":"2025-10-29T05:55:55+00:00"},{"url":"https://www.theblock.co/linked/144491/stablecoin-dex-saddle-finance-hacked-for-10-million","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/single/saddle-finance-loses-more-than-11-million-to-hack","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830011511/https://www.web3isgoinggreat.com/single/saddle-finance-loses-more-than-11-million-to-hack","credibility":3,"archive_timestamp":"2026-08-30T01:15:11+00:00"},{"url":"https://rekt.news/saddle-finance-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260806195626/https://rekt.news/saddle-finance-rekt","credibility":3,"archive_timestamp":"2026-08-06T19:56:26+00:00"},{"url":"https://blocksec.com/blog/blocked-saddle-finance-attack-industry-s-first-influential-blocking-to-rescue-3-800-000","name":"","type":"other","archive_url":"http://web.archive.org/web/20260708002508/https://blocksec.com/blog/blocked-saddle-finance-attack-industry-s-first-influential-blocking-to-rescue-3-800-000","credibility":3,"archive_timestamp":"2026-07-08T00:25:08+00:00"},{"url":"https://finance.yahoo.com/news/venture-backed-saddle-finance-proposes-203900725.html","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829133444/https://finance.yahoo.com/news/venture-backed-saddle-finance-proposes-203900725.html","credibility":3,"archive_timestamp":"2026-08-29T13:34:44+00:00"},{"url":"https://blofin.com/news/saddle-finance-plans-to-wind-down-airdrop-arb-to-sdl-and-vesdl-holders","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bsc.news/post/saddle-finance-decides-to-wind-down-distributes-treasury-to-holders","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://beincrypto.com/defi-exploits-continue-to-plague-industry-as-saddle-finance-hack-sees-10m-stolen/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:49.713286+00:00","updated_at":"2026-08-30T01:16:33.91567+00:00"}}