{"investigation":{"slug":"seneca","entity_name":"Seneca","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Seneca is a decentralized stablecoin lending protocol that allowed users to mint senUSD against collateral. On February 28, 2024, attackers exploited a critical arbitrary external-call vulnerability in its Chamber contract, draining approximately $6.4 million from user wallets across Ethereum and Arbitrum. Approximately 80% of stolen funds were recovered after an on-chain bounty offer; however, the vulnerability had been publicly identified months before the exploit and the team proceeded to launch without patching it.","sections":[{"content":"Seneca is a DeFi lending protocol that enabled users to deposit liquid staking tokens (LSTs) and other crypto assets as collateral to mint a stablecoin called senUSD. The protocol issued a native governance token, SEN, traded on Ethereum. The protocol operated on both Ethereum mainnet and Arbitrum. The team behind Seneca remained largely anonymous with no publicly identified founders throughout the protocol's lifespan.","heading":"Overview","sources":[{"url":"https://www.theblock.co/post/279761/stablecoin-protocol-seneca-hit-by-6-million-exploit-due-to-smart-contract-flaw","name":"theblock.co","type":"other","credibility":3},{"url":"https://rekt.news/seneca-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://crypto.news/seneca-breach-sen-drops/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 28, 2024, Seneca's Chamber smart contract was exploited for approximately $6.4 million. The root cause was an arbitrary external call vulnerability inside the Chamber::performOperations function. This function accepted an action value of 30 (OPERATION_CALL), which triggered the internal _call function and allowed the caller to specify any target contract address and arbitrary calldata. Attackers crafted a transferFrom() call on collateral token contracts, specifying user wallet addresses as senders and their own address as recipient. Because the Chamber contract held unlimited token approvals from users, the unauthorized transfers succeeded. The exploit affected assets primarily in ETH and liquid staked tokens (LSTs) on Ethereum mainnet and Arbitrum. Affected assets included more than 1,900 ETH and 50,000 senUSD. A critical compounding factor was that the Chamber contract lacked a functional pause/unpause mechanism; the pause function was marked internal and could not be called externally, preventing the team from halting the drain once the attack was detected.","heading":"February 2024 Exploit","sources":[{"url":"https://rekt.news/seneca-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://blockapex.io/seneca-protocol-hack-analysis/","name":"blockapex.io","type":"other","credibility":3},{"url":"https://www.cyfrin.io/blog/seneca-attack-hack-analysis-proof-of-concept","name":"cyfrin.io","type":"other","credibility":3},{"url":"https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","name":"protos.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/seneca","name":"revoke.cash","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability exploited in February 2024 was identified at least as early as November 15, 2023, during a competitive audit contest Seneca held on the Sherlock platform. A security researcher identified as 'cawfree' (also referred to as Daniel Von Fange) reportedly flagged the exact flaw during the contest. Rather than address the finding, Seneca abruptly canceled the Sherlock audit contest, citing 'potential code licensing issues,' and launched the protocol approximately five days later without patching the identified vulnerability. Community members who subsequently raised alarms about the vulnerability were allegedly banned from Seneca's Discord server. In December 2023, the team engaged Halborn Security for an audit. Halborn's audit did not flag this specific arbitrary call issue, and the team deployed the contract with the vulnerability intact. Post-exploit communications from the Seneca team attributed the miss to Halborn's audit scope rather than acknowledging the team's decision to cancel the earlier Sherlock contest where the bug had been found.","heading":"Prior Knowledge of Vulnerability","sources":[{"url":"https://rekt.news/seneca-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","name":"protos.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/120m-rug-pulls-new-serial-hacker-arises-and-the-seneca-debacle-crypto-crimes-report-february-4a4955019ddc","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/seneca-recovers-80-of-funds-after-6-4m-exploit/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Seneca team sent an on-chain message to the attacker's address proposing a 20% bug bounty in exchange for return of the remaining 80% of stolen funds and a promise of no legal action. On February 29, 2024, the attacker complied, returning approximately 1,537 ETH (worth roughly $5.3 million) to Seneca's Gnosis Safe address. The attacker retained approximately 300 ETH (split into two addresses of 150 ETH each) as the negotiated bounty, valued at approximately $1 million to $1.28 million. The net unrecovered loss to the protocol and its users was approximately $1 million.","heading":"Fund Recovery","sources":[{"url":"https://cointelegraph.com/news/seneca-hacker-returns-stolen-funds-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://crypto.news/seneca-protocol-hacker-returns-5-3m-from-the-6-4m-breach/","name":"crypto.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/seneca-recovers-80-of-funds-after-6-4m-exploit/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/seneca-hacker-returns-5-3m-amid-legal-threats-keeps-1m-bounty/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Several patterns of conduct raised community trust concerns before and after the exploit. The team deleted references to the exploit from Seneca's Discord server and allegedly removed users who attempted to warn others about the vulnerability both before and during the attack. A since-deleted tweet attributed to team members allegedly featured boasts about 'pristine code' alongside criticism of the Sherlock audit platform that had identified the vulnerability. After the exploit, team communications deflected responsibility toward Halborn's audit rather than acknowledging the decision to deploy code with a known flaw. The protocol's team remained anonymous throughout, with no publicly named founders or developers. The Seneca post-mortem was published to the team's Mirror address (0x289D0033d536eb3Ff53367f0A8CceA00d4Ac63a0) but access to the full document was unavailable at time of investigation.","heading":"Team Conduct and Transparency Concerns","sources":[{"url":"https://rekt.news/seneca-protocol-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","name":"protos.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/120m-rug-pulls-new-serial-hacker-arises-and-the-seneca-debacle-crypto-crimes-report-february-4a4955019ddc","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the February 28, 2024 exploit, the SEN token price dropped between 65% and 80% within a single day, falling from approximately $0.10 to under $0.04. The token subsequently ranked below the top 40,000 cryptocurrencies by market capitalization (ranked approximately #43,670). The Seneca token (SEN) is an ERC-20 contract on Ethereum at address 0xcb19b6b4971bd4206bab176c75b1efe3e28ee5a8.","heading":"Token and Market Impact","sources":[{"url":"https://crypto.news/seneca-breach-sen-drops/","name":"crypto.news","type":"other","credibility":3},{"url":"https://etherscan.io/token/0xcb19b6b4971bd4206bab176c75b1efe3e28ee5a8","name":"etherscan.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/seneca","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Seneca exploit was structurally distinct from most protocol hacks in that it drained funds directly from users' wallets via standing token approvals, rather than from a liquidity pool or treasury. Any user who had granted token approvals to Seneca's Chamber contract addresses on Ethereum or Arbitrum remained at risk until those approvals were explicitly revoked. Seneca instructed users to revoke approvals immediately following the exploit. Revoke.cash listed Seneca as an affected protocol and provided a checker tool for users to identify and revoke outstanding approvals.","heading":"User Risk: Token Approvals","sources":[{"url":"https://revoke.cash/exploits/seneca","name":"revoke.cash","type":"other","credibility":3},{"url":"https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","name":"protos.com","type":"other","credibility":3},{"url":"https://rekt.news/seneca-protocol-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-11-15","event":"Security researcher 'cawfree' (Daniel Von Fange) identifies the arbitrary external call vulnerability in Seneca's Chamber contract during a Sherlock competitive audit contest.","source":""},{"date":"2023-11-15","event":"Seneca abruptly cancels the Sherlock audit contest, citing 'potential code licensing issues,' and announces a launch in five days without addressing the identified vulnerability.","source":""},{"date":"2023-11-20","event":"Seneca Protocol launches on Ethereum and Arbitrum with the known vulnerability present in deployed contracts.","source":""},{"date":"2023-12","event":"Halborn Security completes an audit of Seneca's contracts. The arbitrary call vulnerability is not flagged. The protocol continues operating.","source":""},{"date":"2024-02-28","event":"Attacker exploits the Chamber contract's performOperations function, draining approximately $6.4 million (1,900+ ETH and 50,000 senUSD) from user wallets across Ethereum and Arbitrum.","source":""},{"date":"2024-02-28","event":"Seneca team acknowledges the exploit, instructs users to revoke token approvals, and notes that contracts cannot be paused. Team begins deleting exploit-related messages from Discord and bans users discussing the incident.","source":""},{"date":"2024-02-28","event":"Seneca sends an on-chain message to the attacker offering a 20% bounty (approximately $1.28 million) in exchange for return of 80% of funds and no legal action.","source":""},{"date":"2024-02-29","event":"Attacker returns approximately 1,537 ETH (~$5.3 million) to Seneca's Gnosis Safe address, accepting the bounty proposal. The attacker retains approximately 300 ETH (~$1 million).","source":""},{"date":"2024-02-29","event":"SEN token price drops 65–80% from pre-exploit levels following public disclosure of the exploit.","source":""}],"sources_used":[{"url":"https://rekt.news/seneca-protocol-rekt","name":"Seneca Protocol - REKT News","type":"news_article","archive_url":"http://web.archive.org/web/20260313110810/https://rekt.news/seneca-protocol-rekt","credibility":2,"archive_timestamp":"2026-03-13T11:08:10+00:00"},{"url":"https://www.theblock.co/post/279761/stablecoin-protocol-seneca-hit-by-6-million-exploit-due-to-smart-contract-flaw","name":"Stablecoin protocol Seneca hit by $6 million exploit - The Block","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockapex.io/seneca-protocol-hack-analysis/","name":"Seneca Protocol Hack Analysis - BlockApex","type":"research","archive_url":"http://web.archive.org/web/20260630043107/https://blockapex.io/seneca-protocol-hack-analysis/","credibility":2,"archive_timestamp":"2026-06-30T04:31:07+00:00"},{"url":"https://www.cyfrin.io/blog/seneca-attack-hack-analysis-proof-of-concept","name":"Exploit Analysis and Proof of Concept: Seneca Attack - Cyfrin","type":"research","archive_url":"https://web.archive.org/web/20260725084108/https://www.cyfrin.io/blog/seneca-attack-hack-analysis-proof-of-concept","credibility":2,"archive_timestamp":"2026-07-25T08:41:08+00:00"},{"url":"https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","name":"Seneca Protocol hack highlights dangers of Ethereum token approval mechanism - Protos","type":"news_article","archive_url":"http://web.archive.org/web/20260422150715/https://protos.com/seneca-protocol-hack-highlights-dangers-of-ethereums-token-approval-mechanism/","credibility":2,"archive_timestamp":"2026-04-22T15:07:15+00:00"},{"url":"https://cointelegraph.com/news/seneca-hacker-returns-stolen-funds-exploit","name":"Seneca stablecoin hacker returns stolen funds - CoinTelegraph","type":"news_article","archive_url":"http://web.archive.org/web/20260414055857/https://cointelegraph.com/news/seneca-hacker-returns-stolen-funds-exploit","credibility":2,"archive_timestamp":"2026-04-14T05:58:57+00:00"},{"url":"https://cryptopotato.com/seneca-recovers-80-of-funds-after-6-4m-exploit/","name":"Seneca Recovers 80% of Funds After $6.4M Exploit - CryptoPotato","type":"news_article","archive_url":"http://web.archive.org/web/20260120213335/https://cryptopotato.com/seneca-recovers-80-of-funds-after-6-4m-exploit/","credibility":2,"archive_timestamp":"2026-01-20T21:33:35+00:00"},{"url":"https://crypto.news/seneca-breach-sen-drops/","name":"Seneca Protocol experiences $6m breach, SEN drops 65% - Crypto News","type":"news_article","archive_url":"http://web.archive.org/web/20251107214539/https://crypto.news/seneca-breach-sen-drops/","credibility":2,"archive_timestamp":"2025-11-07T21:45:39+00:00"},{"url":"https://crypto.news/seneca-protocol-hacker-returns-5-3m-from-the-6-4m-breach/","name":"Seneca Protocol hacker returns 5.3M from 6.4M breach - Crypto News","type":"news_article","archive_url":"http://web.archive.org/web/20251012043521/https://crypto.news/seneca-protocol-hacker-returns-5-3m-from-the-6-4m-breach/","credibility":2,"archive_timestamp":"2025-10-12T04:35:21+00:00"},{"url":"https://cryptonews.com/news/seneca-hacker-returns-5-3m-amid-legal-threats-keeps-1m-bounty/","name":"Seneca Hacker Returns 5.3M Amid Legal Threats - CryptoNews","type":"news_article","archive_url":"http://web.archive.org/web/20250907173016/https://cryptonews.com/news/seneca-hacker-returns-5-3m-amid-legal-threats-keeps-1m-bounty/","credibility":2,"archive_timestamp":"2025-09-07T17:30:16+00:00"},{"url":"https://blockapex.medium.com/seneca-protocol-hack-analysis-546f3bcc1040","name":"Seneca Protocol Hack Analysis - BlockApex on Medium","type":"research","archive_url":"http://web.archive.org/web/20250729023256/https://blockapex.medium.com/seneca-protocol-hack-analysis-546f3bcc1040","credibility":2,"archive_timestamp":"2025-07-29T02:32:56+00:00"},{"url":"https://revoke.cash/exploits/seneca","name":"2024 Seneca Hack: Check If You Are Affected - Revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260415040332/https://revoke.cash/exploits/seneca","credibility":2,"archive_timestamp":"2026-04-15T04:03:32+00:00"},{"url":"https://medium.com/coinmonks/120m-rug-pulls-new-serial-hacker-arises-and-the-seneca-debacle-crypto-crimes-report-february-4a4955019ddc","name":"Crypto Crimes Report February 2024 - NEFTURE Security via Coinmonks","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://etherscan.io/token/0xcb19b6b4971bd4206bab176c75b1efe3e28ee5a8","name":"SEN Token on Etherscan","type":"on_chain","archive_url":"http://web.archive.org/web/20260724164050/https://etherscan.io/token/0xcb19b6b4971bd4206bab176c75b1efe3e28ee5a8","credibility":1,"archive_timestamp":"2026-07-24T16:40:50+00:00"},{"url":"https://defillama.com/protocol/seneca","name":"Seneca Protocol TVL - DefiLlama","type":"on_chain","archive_url":"http://web.archive.org/web/20250909230212/https://defillama.com/protocol/seneca","credibility":2,"archive_timestamp":"2025-09-09T23:02:12+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:34.724102+00:00","updated_at":"2026-08-29T01:34:33.66+00:00"}}