Security incident · 2022-05-01
Rari Capital
According to the public DefiLlama incident dataset, Rari Capital (Ethereum, Arbitrum) suffered a security incident on 2022-05-01, with about $80.0M reported lost.
| Date | 2022-05-01 |
|---|---|
| Reported loss | $80.0M |
| Chain | Ethereum, Arbitrum |
| Target type | DeFi Protocol |
| Technique class | Reentrancy |
| Technique | Reentrancy |
| Bridge incident | No |
| Within 2022 | #11 by loss that year, 2.2% of all reported losses that year |
How this kind of attack works
The contract sent funds before updating balances, and the attacker re-entered during the transfer to withdraw repeatedly.
Would a pre-payment check have helped
Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.
Other incidents with the same technique
- Curve DEX2023-07-30 · $61.7M
- The DAO2016-06-17 · $60.0M
- GMX V1 Perps2025-07-09 · $42.0M
- Grim Finance2021-12-18 · $30.0M
- Penpie2024-09-03 · $27.0M
- dForce Lending2020-04-19 · $25.0M

