Open Source ·
SushiSwap MISO redirected auction proceeds
A contractor with MISO front-end access changed an auction payout address in September 2021. The malicious commit redirected 864.8 ETH before the funds were returned.
SushiSwap's MISO launchpad was attacked through source control, not through a smart-contract bug. A contractor account with access to the front-end repository changed the address used by the Jay Pegs Auto Mart auction.
The change was small and direct. The commit set the auction contract's payout address at creation, and the contract itself forwarded 864.8 ETH, roughly $3 million at the time, when the auction was finalized. Users were trusting the application surface to point at the right contract path.
Sushi leadership described the incident as a supply-chain attack because the attacker used the project's own repository and deployment path. The malicious code entered the product as a code contribution, not as traffic manipulation after deployment.
The funds were later returned to the operational multisig after public pressure and direct handling by Sushi. The archive keeps the record because the delivery method matters even when the money came back.
Notes
- The sushi.com forum thread cited here is now private and returns a login wall; no Wayback snapshot exists, so it cannot currently be read as a citation.
- Coverage describes a pushed commit to the private sushiswap/miso-studio repository rather than a merged pull request; whether it passed review is not established.
Appendix · Affected releases
References
- Cryptocurrency launchpad hit by $3 million supply-chain attackarstechnica.com
- The MISO Front End Exploit and How We Mitigated Itforum.sushi.com
Source record: oss/attacks/miso-sushiswap/meta.yaml