Security incident · 2017-11-09
Parity Multisig
According to the public DefiLlama incident dataset, Parity Multisig (Ethereum) suffered a security incident on 2017-11-09, with about $150.0M reported lost.
| Date | 2017-11-09 |
|---|---|
| Reported loss | $150.0M |
| Chain | Ethereum |
| Target type | DeFi Protocol |
| Technique class | Access Control |
| Technique | Uninitialized Proxy |
| Bridge incident | No |
| Within 2017 | #1 by loss that year, 51.9% of all reported losses that year |
How this kind of attack works
A contract function meant for administrators was not locked down, and the attacker called it directly to move funds.
Would a pre-payment check have helped
Broken contract permissions are a code-audit matter that pre-payment screening cannot see.
Other incidents with the same technique
- Poly Network2021-08-10 · $611.0M
- Drift Trade2026-04-01 · $295.0M
- BitGrail2018-02-12 · $170.0M
- Mirror2021-10-08 · $90.0M
- UPCX2025-04-01 · $70.0M
- Munchables2024-03-26 · $62.5M

