Skip to main content
AVOID.NET

Seneca

avoid.net/seneca→22/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·QND8vE…JgRK

Summary

Seneca is a decentralized stablecoin lending protocol that allowed users to mint senUSD against collateral. On February 28, 2024, attackers exploited a critical arbitrary external-call vulnerability in its Chamber contract, draining approximately $6.4 million from user wallets across Ethereum and Arbitrum. Approximately 80% of stolen funds were recovered after an on-chain bounty offer; however, the vulnerability had been publicly identified months before the exploit and the team proceeded to launch without patching it.

Connected Entities

4 entities · 60 linked investigations
Organizations
Protocols
Relationships
  • Arbitrum→mentioned with→Ethereum(80%)
  • Seneca Protocol→mentioned with→Ethereum(80%)
  • Seneca Protocol→mentioned with→Arbitrum(70%)
  • Seneca Protocol→mentioned with→Seneca(80%)
  • Seneca→mentioned with→Ethereum(80%)
  • Seneca→mentioned with→Arbitrum(70%)
  • Seneca→mentioned with→Seneca Protocol(80%)
Have evidence about Seneca?

Timeline(9 events)

15 November 2023

Security researcher 'cawfree' (Daniel Von Fange) identifies the arbitrary external call vulnerability in Seneca's Chamber contract during a Sherlock competitive audit contest.

15 November 2023

Seneca abruptly cancels the Sherlock audit contest, citing 'potential code licensing issues,' and announces a launch in five days without addressing the identified vulnerability.

20 November 2023

Seneca Protocol launches on Ethereum and Arbitrum with the known vulnerability present in deployed contracts.

December 2023

Halborn Security completes an audit of Seneca's contracts. The arbitrary call vulnerability is not flagged. The protocol continues operating.

28 February 2024

Attacker exploits the Chamber contract's performOperations function, draining approximately $6.4 million (1,900+ ETH and 50,000 senUSD) from user wallets across Ethereum and Arbitrum.

28 February 2024

Seneca team acknowledges the exploit, instructs users to revoke token approvals, and notes that contracts cannot be paused. Team begins deleting exploit-related messages from Discord and bans users discussing the incident.

28 February 2024

Seneca sends an on-chain message to the attacker offering a 20% bounty (approximately $1.28 million) in exchange for return of 80% of funds and no legal action.

29 February 2024

Attacker returns approximately 1,537 ETH (~$5.3 million) to Seneca's Gnosis Safe address, accepting the bounty proposal. The attacker retains approximately 300 ETH (~$1 million).

29 February 2024

SEN token price drops 65–80% from pre-exploit levels following public disclosure of the exploit.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:34 AM

last updated: 8/29/2026, 1:34:33 AM

4 views

avoid.net — verified advice for a post-truth world