Silo Finance, a decentralized lending protocol, recently suffered an exploit on a newly deployed leverage-related smart contract, with roughly $500,000–$545,000 in crypto drained by an attacker who routed funds through Tornado Cash to obfuscate their trail. The affected contract was a pre-release / testing module designed to enable leveraged positions, separate from Silo’s core lending markets and vaults, and funded with Silo DAO’s own assets rather than user deposits. Security firms and on‑chain analysts linked the incident to a vulnerability involving improper validation of user-controlled inputs in the leverage contract’s logic, which allowed an attacker to manipulate parameters and effectively redirect borrow operations and collateral to their own address. According to post-mortems and protocol statements, core Silo contracts remained unaffected, and no user funds were compromised; the loss was limited to DAO-owned funds earmarked for testing the new leverage feature. The attacker funded the exploit wallet via Tornado Cash, a mixing service frequently used in DeFi hacks, highlighting ongoing challenges around tracing and recovering stolen assets. The incident has reinforced concerns about smart contract security in DeFi, especially around experimental or auxiliary modules that may not be as battle-tested as core protocol contracts, and has prompted Silo Finance and its auditors to commit to tighter input validation, broader security reviews, and enhanced monitoring before deploying new functionality.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Silo

Comments