← Radar

Incident case file

Sign in to watch

Renegade.fi Dark Pool V1 — White Hat Initializer Exploit

Incident date May 10, 2026

0 views

ResolvedArbitrumUnprotected initializer / White hatCluster: RENEGADE-ARB-2026-05

Estimated loss

$209K

Victims identified

1
Victim group joining is coming soon.

Investigation

95%

Facts and investigation

Attacker: Anonymous white hat (negotiated on-chain return)

Funds moved to: ~$190K (90%) returned to protocol within 45 minutes; ~$19K retained as bug bounty
White hat exploited an unprotected initializer in the Renegade.fi Dark Pool V1 proxy contract on Arbitrum. A faulty migration from April 2025 had left the version counter desynchronized, exposing initialize() to re-entry. The white hat injected malicious logic, used delegatecall to drain 27 distinct ERC-20 tokens from the proxy storage, then negotiated a return after Renegade offered a 10% bounty.

Timeline: On May 10, 2026, an anonymous white hat exploited an unprotected initializer in Renegade.fi's V1 dark pool proxy contract on Arbitrum. The vulnerability stemmed from a faulty contract migration during a software update in April 2025, which had left the version counter desynchronized and made the initialize() function callable again. The white hat extracted approximately $209,000 across 27 distinct ERC-20 tokens via delegatecall to malicious logic. Renegade publicly offered a 10% bounty within 45 minutes of detection; the white hat accepted and returned ~$190K (approximately 90%) of the funds. The net loss to the protocol was ~$19K. The exploit was scoped strictly to the V1 Arbitrum deployment, which was paused; other Renegade deployments were confirmed unaffected. The team committed to fully compensating users for the residual loss.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)