1 August 2026
Yield Farmer Got Scammed For $140,000 In Uniswap (UNI) Tokens
Alex Manuskin is a researcher at ZenGo and today he revealed a shocking incident of Uniswap. He tweeted that “yield farming” project UniCats allegedly stole nearly $200,000 worth of Uniswap (UNI) tokens from several ethereum users.
Manuskin stated that UniCats added a “backdoor” to the yield farming smart contract and this allows the platform to have full control over its users’ tokens even after users withdrew it from the farming pool.
Manuskin shared that an anonymous user, named “Jhon Doe” for privacy reasons, apparently lost $140,000 worth of UNI as a result of this scam. According to him, Doe would have fallen for the scam under the assumption that farming with UniCats would lead to “the next YFI” like success.
Generally, yield farming Dapps asks for users’ permission to spend an infinite number of tokens, and the user in question consented to a similar request seen in the image below:
The second step researcher included an etherscan tracking report to show that the user would have farmed “some $MEOW,” and then decided to pull out all of the UNI tokens from the pool.
Manuskin explained this in a tweet:
What Jhon doesn’t know, is that once you approve the contract to use ∞ tokens, the contract can take their tokens at any time. Even after they were withdrawn from the farming scheme.
To make it difficult to track, UniCats developers created new smart contracts “for each new victim” and the stolen bulks of 100ETH shall be moved into Tornado Cash by developers. Tornado Cash is experimental software and a privacy mixer for Ethereum that makes the process of tracing the place of funds extremely difficult.
Manuskin in his research states that this scam would be a first, especially to take advantage of their own farming pools protocols.
Recently, a decentralized liquidity provider, Bancor was attacked by hackers who found a similar backdoor vulnerability on its smart contract protocol, which led to a loss of user funds.
Discussion
0 comments