Dango perpetuals protocol exploited via insurance fund logic bug; attacker drained USDC collateral from perps contract.
Security & Exploits ·
Dango's perpetuals protocol experienced a security incident involving its insurance fund logic. An attacker exploited a flaw that allowed donations to the insurance fund without validating that the donation amount was positive, using this to drain USDC collateral from the perps contract. The vulnerability has been isolated to the insurance fund donation logic, which has now been removed, and does not affect order matching, PnL settlement, liquidation, or other trading system components.
The damage was partially contained by a bridge rate limit. The attacker successfully moved $410,010 USDC to Ethereum, but $1,490,012 in exploited funds remained on Dango and recoverable. Dango paused its chain and began recovering the trapped funds from the attacker's account (0x023ef9e3e20caca6ef3743cbfba6469d69978999 on Dango, 0x271d1f2f4194e61f2a17ea82d82e31cea9f6762a on Ethereum).
Dango stated all affected users will be fully compensated and the protocol will resume normal operations soon. The team contacted SEAL_911, which notified Circle and major exchanges. Dango extended an invitation to the attacker to negotiate a bug bounty. The points program has been postponed.