Saddle Finance
Summary
Saddle Finance was an Ethereum-based automated market maker (AMM) optimized for pegged-value assets such as stablecoins and wrapped BTC, founded in 2020 and launched in January 2021. The protocol suffered a critical exploit on April 30, 2022, when an attacker leveraged an unpatched MetaSwapUtils library bug to drain approximately $11 million via flash-loan-assisted price manipulation, with $3.8 million subsequently rescued by security firm BlockSec. The protocol formally wound down in September 2023 following a DAO vote (SIP-54) triggered in part by the broader DeFi security climate after the Curve Finance hack.
Connected Entities
1 entitiesTimeline(11 events)
2021-01-19
Saddle Finance launches on Ethereum mainnet and simultaneously closes $4.3 million seed round from Coinbase Ventures, Electric Capital, Polychain Capital, Alameda Research, and others.
2021-01-19
Within six minutes of launch, three arbitrageurs extract approximately 7.9 BTC (~$275,000) from newly seeded pools by exploiting price imbalances; team response places responsibility on users.
2021-01-20
Curve Finance publicly accuses Saddle Finance of copying its StableSwap algorithm without attribution, citing a Quantstamp audit finding that Saddle's code was ported directly from Curve's contracts.
2021-11-11
Saddle raises $7.5 million Series A round led by Electric Capital, bringing total funding to approximately $11.8 million.
2021-11-01
Forks of Saddle's code (Nerve Finance, Synapse Protocol) are exploited using the MetaSwapUtils VirtualPrice pricing bug, alerting the Saddle team to the vulnerability class.
2021-12-01
Saddle deploys a patched MetaSwapUtils library addressing the VirtualPrice LP token calculation bug, but fails to migrate existing sUSD metapool to use the corrected code.
2022-04-30
Attacker (0x63341ba917de90498f3903b199df5699b4a55ac0, funded via Tornado Cash) drains approximately 3,932 ETH (~$11 million) from the sUSD-saddleUSD-V2 metapool across two successful flash-loan exploit transactions.
2022-04-30
BlockSec detects the exploit in real time and executes rescue transaction 0x9549c0cb... at block 14684434, recovering approximately 1,360 ETH ($3.8 million) from a blocked third attack attempt.
2022-04-30
Rari Capital and Fei Protocol suffer a separate $80 million reentrancy exploit on the same day, compounding DeFi sector stress.
2023-08-08
Founder Sunil Srivatsa submits SIP-54 to Saddle DAO proposing protocol wind-down by September 30, 2023, citing the Curve Finance hack as a renewed reminder of smart contract risk.
2023-09-30
Saddle Finance formally shuts down; all pools paused, community multisig dissolved, DAO treasury distributed to SDL and veSDL token holders as ARB airdrop.
Decision Log
- hash: GvqTBmiZ2z3PNvpXhKtD7WLYYWEZnx548AeX92yivgzq
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:49 AM
last updated: 5/20/2026, 6:59:03 PM
avoid.net — verified advice for a post-truth world