ElasticSwap
Summary
ElasticSwap was an Avalanche-first AMM protocol specializing in elastic supply tokens, which launched in May 2022 and was exploited in December 2022 for approximately $854,000 via flash loan attacks that exploited an accounting inconsistency between its addLiquidity and removeLiquidity functions. The vulnerability class that enabled the exploit had been identified in a Code4rena security audit conducted ten months earlier but was not adequately remediated before deployment. The protocol recovered approximately 55% of user funds through a bounty program and community vote, but the TIC governance token lost over 70% of its value and the protocol appears to have ceased meaningful activity.
Connected Entities
1 entities · 10 linked investigationsTimeline(10 events)
2021-01-01
ElasticSwap founders launch ElasticDAO, the predecessor project, on Ethereum.
ElasticSwap Medium2022-01-20
Code4rena competitive audit begins for ElasticSwap smart contracts. Auditors identify high-severity vulnerability H-02: direct token transfers to pool contracts can inflate balances and enable value extraction via removeLiquidity.
Code4rena Audit Report2022-01-26
Code4rena audit contest closes. Nine unique vulnerabilities identified including two high-severity findings.
Code4rena Audit Report2022-05-11
ElasticSwap protocol and AMM interface launch on Avalanche with an AMPL liquidity pool. TIC governance token goes live.
ElasticSwap Medium2022-05-01
ElasticSwap announces strategic partnerships with Big Brain Holdings, ShapeShift, Ampleforth, Connext, and Nomad, and plans multi-chain expansion to Polygon, Arbitrum, and Fantom.
ElasticSwap Medium — What's Next2022-12-12
Three separate flash loan attacks exploit ElasticSwap on Avalanche and Ethereum chains. Attackers exploit accounting inconsistency between addLiquidity (constant K) and removeLiquidity (live balance) to drain liquidity pools. Total stolen: approximately $854,000.
CertiK — ElasticSwap Incident Analysis2022-12-13
ElasticSwap announces the exploit publicly on Twitter at approximately 07:33 AM UTC and urges all users to remove liquidity immediately. TIC token price falls more than 70%.
CertiK — ElasticSwap Incident Analysis2022-12-14
MEV bot operator who front-ran the Ethereum attacker agrees to return 400.5 ETH to ElasticSwap treasury under the bounty program, retaining approximately 44.5 ETH as a bounty fee.
QuillAudits — Decoding Elastic Swap's $854K Exploit2022-12-15
ElasticSwap team initiates community governance vote on how to manage recovered assets while developing refund proposals for affected users.
CertiK — ElasticSwap Incident Analysis2023-01-22
ElasticSwap team publishes JSON files documenting aggregate losses by address across all chains. Treasury multisig holds approximately 487 ETH ($625,000). Approximately 55% of user funds recovered total; 50.89% of users vote to convert recovered assets proportionally for reimbursement.
CertiK — ElasticSwap Incident AnalysisDecision Log
- hash: b5CAnm6mbbudoQCwezk6b7EUyd7yRYCDeyhhWvzmwg3
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:45 AM
last updated: 5/30/2026, 12:11:33 PM
avoid.net — verified advice for a post-truth world