On 15 July 2026, Sonic DEX experienced a sophisticated exploit that resulted in the unauthorized extraction of assets from multiple liquidity pools.
Since the incident, our engineering and security teams have conducted an extensive investigation to determine exactly how the attack occurred, trace the movement of the stolen funds, and coordinate with centralized exchanges and law enforcement.
This post provides a detailed overview of our findings and the actions we are taking
Summary
-
Incident Date: 15 July 2026
-
Estimated Loss: Estimated $276,000
-
Liquidity Pools Affected: 26
-
Root Cause: Transaction atomicity vulnerability triggered through asynchronous canister execution
-
Current Status:
-
Vulnerability identified
-
Attack fully analyzed
-
Funds traced on-chain
-
Exchanges notified
-
Law enforcement process underway
-
Our forensic investigation traced the stolen assets through multiple intermediary wallets, swaps, and cross-chain transfers before they were ultimately converted to Bitcoin and deposited at HitBTC exchange.
Technical Analysis (Basic Analysis)
After a comprehensive review of the attack, we identified a transaction atomicity vulnerability within the Sonic DEX swap endpoints. The issue stemmed from the asynchronous execution model used by Internet Computer canisters. Under carefully orchestrated conditions, an attacker was able to submit a large number of precisely timed asynchronous requests that manipulated execution ordering during intermediate state transitions. Instead of following the expected execution sequence, the requests created race conditions within the task queue. This broke the expected transactional atomicity of the swap process.
As a result, the attacker was able to extract funds before the protocol completed reconciliation of the final transaction state. The exploit did not rely on compromised private keys or administrative privileges. Instead, it exploited an edge case in the protocol’s execution flow.
Root Cause
Our investigation determined that the exploit was caused by:
-
asynchronous execution ordering,
-
race conditions during intermediate state transitions,
-
loss of transactional atomicity under concurrent execution,
-
unauthorized state transitions before final reconciliation.
The attacker repeatedly executed carefully coordinated requests at high frequency, allowing them to exploit these timing conditions to withdraw assets that should not have been available. Following identification of the vulnerability, we immediately disabled the affected functionality and began implementing architectural changes to eliminate this class of issue.
On-Chain Investigation
In parallel with identifying the technical root cause, our team conducted a comprehensive forensic investigation to trace every movement of the stolen assets on-chain.
The investigation reconstructed the complete transaction flow from the affected Sonic DEX liquidity pools to the attacker’s final cash-out destination.
Our findings show that the attacker:
-
Drained assets from 26 concentrated liquidity pools, resulting in an estimated loss of approximately $276,000.
-
Consolidated approximately $195,000 into the primary attacker wallet:
- abgpi-7mp67-kkjkv-l4hft-4bkxv-nd2gi-uyidc-xd6vh-tay7a-krima-vae
-
Distributed smaller amounts across three secondary wallets:
-
4e18c7452ec8a54c87c3751b6e93ab2b26d5ada04ecdacc63452b4b945c5e580
-
3a6a4f43d0da28574844cc7237bb8339ca33e378f5f03edb47ad5e02502a91de
-
6d123e9bc79ea9f2ced187b8c58338341ef49cacb02792bbdb37ef455d27da74
-
The attacker then followed a structured laundering process:
1. Relay Wallet
The attacker transferred 96,780 ICP through the relay wallet: d154feac98eb916d77078abbeec34166daac0c3b80a15ee2ea055d21f3dbdfd9 This wallet was used solely as a temporary laundering step before the funds were moved again.
2. ICPSwap Conversion
The stolen ICP was swapped into ckBTC through the ICPSwap ckBTC/ICP Pool: (Canister:
xmiu5-jqaaa-aaaag-qbz7q-cai)
At the same time, approximately 30 million BOOM tokens were liquidated through the ICPSwap BOOM Pool: (Canister: fdno6-ayaaa-aaaag-qckuq-cai)
3. Consolidation
After the swaps, both the ckBTC and BOOM proceeds were consolidated into: tq34e-t2u7t-uernl-4p7re-mlcwv-6srpn-gu32m-g5iv5-i4rsi-2nacq-rae
This wallet served as the central aggregation point before the cross-chain transfer.
4. Bitcoin Exit
The attacker converted approximately 3.145 BTC from ckBTC into native Bitcoin through 62 separate burn transactions, sending the funds to the Bitcoin staging wallet: bc1qyf5f4nm66yuaga8zjs809lslmt3fapt68uhly4
5. Peel Chain
To make tracing more difficult, the attacker split the Bitcoin into multiple single-use peel-chain wallets before reconverging the funds into a centralized exchange (HitBTC) deposit transaction.
The final exchange deposit transaction identified by our investigation is:
Transaction ID :1aeea09d80ebf99f21df94792db3d65f86f1935e42f7e70b8bba379885da0aad
Timestamp: 2026-07-16 03:40 UTC
6. Centralised Exchange (HitBTC)
Our forensic investigation ultimately traced the funds to the following Bitcoin deposit address hosted by a centralized exchange (HitBTC): bc1qdfl3dfnwwvlqa5jpckh0ccwpjczh5y566c4g76
Based on our forensic findings, we contacted centralized exchanges that were connected to the movement of funds. We provided detailed transaction records, wallet traces, and forensic evidence. The exchanges acknowledged receipt of our reports and confirmed their willingness to cooperate with official law enforcement investigations where legally permitted.
As part of our ongoing investigation, we identified another important lead. Approximately one month prior to the exploit, the attacker-controlled wallet received funds from another wallet, providing an additional avenue.
Law Enforcement
We are actively working with the appropriate authorities to pursue this investigation. Our forensic report identifies the complete on-chain trail up to the centralized exchange deposit. Identification of the individual behind the exchange account requires information held by the exchange and the appropriate legal process.
We will continue cooperating with investigators and provide any additional evidence required.
Security Improvements & The Next Chapter for Sonic
While addressing the security incident has been our immediate priority, we have also taken this opportunity to redefine the future of Sonic.
Over the past several months, our engineering team has been redesigning the platform from the ground up with a stronger focus on security, performance, and long-term sustainability.
As part of this transformation, we have made the strategic decision to sunset the Liquidity Pool (LP) protocol and evolve Sonic into a next-generation platform centered around AI-powered discovery, market analytics, token aggregation, and investing tools.
Our objective is not simply to recover from this incident, but to relaunch Sonic as a stronger, more secure, and more innovative platform than ever before. The upcoming version of Sonic represents a new chapter for the project—one that combines robust security with powerful new products designed to make on-chain investing more accessible, intelligent, and user-friendly.
We look forward to sharing more details, previews, and launch timelines with our community in the coming weeks.
User Compensation Portal
While our investigation and recovery efforts continue, we are also committed to supporting affected members of the Sonic community. To begin this process, we will launch a dedicated compensation portal next week where eligible users can submit:
-
Their wallet address
-
Information about their affected Sonic DEX assets
-
Supporting details required for verification
Our team will review every submission and verify the reported balances against our on-chain records. Following verification, we intend to compensate eligible users either fully or partially, depending on the final recovery process and available funds. Compensation will be distributed directly to the wallet provided during the submission process over the coming month.
At this stage, our commitment is focused on reimbursing regular community users who were directly affected by the exploit. Additional details regarding eligibility, the verification process, compensation methodology, timelines, and any other categories of affected participants will be announced separately before the portal goes live.
We understand the uncertainty this incident has caused, and we are committed to handling the compensation process in a transparent, fair, and accountable manner. More details about the compensation portal, eligibility criteria, and reimbursement process will be published soon
Commitment to the Community
We understand the impact this incident has had on our users and liquidity providers. Transparency is important to us, which is why we are publishing both the technical findings and the forensic analysis of the attack.
We remain fully committed to:
-
pursuing recovery of stolen assets,
-
cooperating with exchanges and law enforcement,
-
strengthening Sonic DEX’s security and product,
-
keeping our community informed as the investigation progresses.
We sincerely appreciate the patience, support, and trust of our community throughout this process.
We will continue to share meaningful updates as they become available.
Thank you ,
Sonic Team.