Maker-side ASB bug exploited to grief liquidity providers
Before the May 27 patch, eigenwallet's maker-side Automated Swap Backend (ASB) failed to sanity-check the Bitcoin cancel-transaction fee. A malicious taker could propose an absurdly high fee and burn value during a swap, griefing the maker. Regular wallet users and takers were never at risk. Attackers used it across four swaps, affecting two market makers and roughly 0.657 BTC. Nothing was stolen: the griefer burned more of their own BTC than they destroyed. eigenwallet shipped fee validation in v4.6.7 within a day and started a reimbursement fund, its donation wallet plus community donations, to cover affected makers in part. Read more Show less
Before the May 27 patch, eigenwallet's maker-side Automated Swap Backend (ASB) failed to sanity-check the Bitcoin cancel-transaction fee. A malicious taker could propose an absurdly high fee and burn value during a swap, griefing the maker. Regular wallet users and takers were never at risk.
Attackers used it across four swaps, affecting two market makers and roughly 0.657 BTC. Nothing was stolen: the griefer burned more of their own BTC than they destroyed. eigenwallet shipped fee validation in v4.6.7 within a day and started a reimbursement fund, its donation wallet plus community donations, to cover affected makers in part.
Stepped down from -5 on resolution · fades to 0 by Aug 2026
Second review following up on this: used it twice in the past with no problems, less than an hour from Bitcoin in to xmr out. Today I'm only seeing about 3 makers available (@ 22:00UTC). I assume they're still recovering/wary of making swaps given the recent vulnerability. Could take longer than usual to find a good price