Renegade.fi Confirms $190K Recovery From Whitehat Following Arbitrum Exploit

11-May-2026 Crypto Economy

TL;DR:

  • A white hat hacker attacked the Renegade protocol and returned nearly $190,000 hours after stealing 27 ERC-20 tokens on Arbitrum.
  • Analytics platform Blockaid detected the $209,000 exploit at 8:27 UTC; the hacker kept 10% as a bounty.
  • Renegade attributed the vulnerability to a faulty migration in its April 2025 update and promised to compensate affected users.

The decentralized dark pools protocol Renegade was attacked on Sunday by a white hat hacker who withdrew 27 ERC-20 tokens from its V1 pool on the Arbitrum network, valued at approximately $209,000 according to blockchain security platform Blockaid, which detected the incident at 8:27 UTC. In less than 45 minutesthe hacker returned nearly $190,000 to the Arbitrum address “0xE4A…5CFBE”, which included $84,370 in USDC, $27,885 in wrapped Bitcoin and $23,950 in wrapped Eth.

The attack was possible because the deployment code did not assign an explicit owner to the smart contract, and a faulty migration in the April 2025 software update allowed anyone to overwrite the contract linked to the V1 pool. The hacker injected malicious logic into a defective function to carry out the theft.

Renegade exploit blockaid

Renegade Managed to Negotiate with the Hacker

Renegade responded to the incident by sending an onchain message in which it offered the hacker 10% of the funds as a bounty in exchange for the return of the remaining 90%, also warning them of potential civil or criminal action if the agreement was not honored.

The hacker complied and justified their actions in a response also recorded on-chain: “Although I understand that what I did was not ethical, in the current context of DeFi cybersecurity, I believe this was the best solution to protect users’ funds.” They also pointed out that the exploited vulnerability was “too simple and severe“, urging the team to strengthen its security measures. The hacker added that actors such as North Korean hackers “would never come to negotiate.”

Renegade explot hacker white hat

The protocol confirmed that only 7% of its trading volume was processed through the affected V1 pool, meaning the operational impact was limited. Renegade committed to contacting affected users directly, compensating them in full and publishing a complete forensic analysis of the incident. Dark pools are private trading platforms designed to execute large transactions without exposing participants’ intentions to the broader market, which makes them sensitive infrastructure within the DeFi ecosystem.

Also read: Impression 3D et contrefaçon : attention, ce que vous imprimez est peut-être illégal
About Author Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc fermentum lectus eget interdum varius. Curabitur ut nibh vel velit cursus molestie. Cras sed sagittis erat. Nullam id ante hendrerit, lobortis justo ac, fermentum neque. Mauris egestas maximus tortor. Nunc non neque a quam sollicitudin facilisis. Maecenas posuere turpis arcu, vel tempor ipsum tincidunt ut.
WHAT'S YOUR OPINION?
Related News