Renegade.fi exploited for $209K via dangling initialize() function left in Stylus proxy upgrade; attacker negotiated 90/10 bounty split and returned most funds.
Security & Exploits ·
A researcher discovered a critical vulnerability in Renegade.fi stemming from a dangling initialize() function left in a 2025 proxy upgrade to a Stylus implementation, which could have remained exploitable for roughly 354 days. Rather than follow standard disclosure practices, the researcher drained all 26 ERC-20 tokens from the protocol in a single transaction worth $209K and posted an on-chain message claiming whitehat status while requesting negotiation.
Renegade responded on-chain with a counteroffer: return 90% of the funds to a fresh address within 72 hours, retain 10% as a bounty, and receive public whitehat framing with no legal consequences. The attacker accepted the terms and returned the majority of funds while keeping roughly $20K in USDC, signing off with a reference to diplomatic negotiation as justification.
The incident reflects a shift in protocol security response strategy: post-exploit negotiation and bounty ratification appear increasingly attractive to projects as a faster and cheaper alternative to fund recovery or legal action. How this precedent influences future vulnerability disclosures and attacker incentives remains unclear.