The Economic Attack
The Attack
On 13 August 2024, the ecosystem experienced one of the most significant disruptions in its history.
An economic attack exposed a vulnerability in protocol economics — not in the protocol's software — that had not previously been observed.
The consequences were immediate.
Value was destroyed.
Markets reacted.
Confidence declined.
Uncertainty spread throughout the community.
For many participants, the experience was devastating.
Years of effort appeared to unravel within a matter of days.
The attack did not merely impact charts and market prices.
It affected people.
Real people.
People who had committed time, resources, energy and belief to the vision.
People who had spent years contributing to the ecosystem.
People who genuinely believed they were helping build something meaningful.
The economic damage was substantial.
The emotional damage was equally significant.
What Happened
The incident arose during a scheduled protocol configuration procedure connected to the introduction of new lending pool and oracle mechanisms.
As part of that procedure, a temporary rate change was applied for a very short period. The configuration window lasted approximately 15 to 30 seconds. During that window, an automated contract detected the temporary rate and executed a sequence of transactions designed to extract value from open-market liquidity pools.
The attacker acquired VOW, routed it through the relevant contract while the temporary rate was active, received an abnormally large amount of vUSD, and then used that vUSD to trade against available liquidity. The attacker contract had been deployed approximately 110 days before the incident and was funded through a Tornado Cash-linked address, making attribution extremely difficult.
The result was a sudden and unintended expansion of vUSD voucher supply into the open market. The underlying VOW supply did not increase. In fact, VOW was burned as part of the transaction path. However, the amount of vUSD created during the attack exceeded the intended economic parameters of the system and placed severe pressure on market liquidity.
It is important to be clear about what this event was and what it was not.
It was not a breach of the VOW token.
It was not a compromise of user wallets.
It was not a theft of private keys.
It was not a software hack in the ordinary sense.
The smart contracts executed according to their coded logic. The vulnerability was economic: an automated attacker exploited the interaction between a temporary configuration state and open-market liquidity. The event revealed an economic attack vector that had not previously been observed in the ecosystem, including during earlier comparable configuration events.
Following the incident, the community and supporting contributors analysed the attack, introduced additional safeguards, and adapted the protocol's economic controls to reduce the risk of comparable attack paths recurring.
We have no definitive answer on who could have set up these contracts to attack the project and why it was done — Analysis continues, and relevant information may be shared with appropriate authorities if attribution becomes possible.
This is our calculation of the total value extracted from the Uniswap pools in the attack.
| Asset | Value |
|---|---|
| 175 ETH | $477,750 |
| 595,000 USDT | $595,000 |
| 5.8M VOW® | $2,320,000 |
| Total | $3,392,750 |
Note: Certik's figure for value extracted by the attacker (~$1.2m) differs from ours because we value VOW at $0.40 — the price on the day before the attack — whereas Certik values VOW at the much lower price reached at the end of the attack.
Technical Breakdown
Independent security researchers at Certik subsequently published their own incident analysis. Their reconstruction lines up with the team's account and provides a useful external view of exactly how the exploit was executed on-chain.

The attack contract had been deployed 110 days prior to the incident and executed within two blocks of the transaction that modified the usdRate. The usdRateSetter had performed similar operations on 22 November 2023 and 1 March 2024 — temporarily changing the rate to 150 and 200 respectively before reverting it to 1. None of those earlier changes were exploited, which suggests the attacker had been monitoring the address for some time and executed automatically as soon as the opportunity arose.
Addresses
- Exploiter wallet:
0x48de6bF9e301946b0a32b053804c61DC5f00c0c3 - Exploit contract:
0xB7F221e373e3F44409F91C233477ec2859261758
Step by step
Two blocks before the attack, the usdRateSetter set the usdRate to 100. Having detected the rate change, the attacker borrowed 1,486,625 VOW from the Uniswap VOW–WETH pool via flash loan and transferred them all to the VSCTokenManager contract in order to burn them in exchange for vUSD.
When the VSCTokenManager receives VOW tokens it calculates the amount of vUSD to mint using the current usdRate. With the rate set to 100, the attacker received 100 vUSD for every VOW burned — minting 148,662,529 vUSD from 1,486,625 VOW.
The attacker then used that vUSD to drain the VOW–vUSD pool, swapping ~148m vUSD for the 59m VOW sitting in the pool. They repaid 1,490,198 VOW to the VOW–WETH pool to close the flash loan, and used the remaining VOW to drain the VOW–USDT and VOW–WETH pools. In total they extracted approximately 175 ETH, 595k USDT and 5.8M VOW of the community's liquidity.
Communication
Throughout the incident the team chose transparency over silence. Updates were posted publicly, in real time, explaining what had happened, what was being done about it, and what holders should and should not do. The cadence and tone of those updates became part of how the ecosystem held together over the following weeks.



What Happened Next
Once the immediate market response had been managed, the question shifted from triage to direction. The VOW Ecosystem Foundation deliberately did not impose a unilateral fix. Instead, the path forward was put to the community in an on-chain vote, with the VOW Ecosystem Foundation's own tokens excluded so that the decision would rest entirely with independent holders.

With a clear mandate from the community, the recovery plan was put into motion. New vcurrency contracts were written from a clean slate, with the lessons of August designed in from the start — tighter controls around any privileged function, no live testing against production liquidity, and a more defensive posture around rate-setting paths.
The new contracts were then submitted for an independent smart contract audit by Hacken, one of the most established security firms in the industry. Although the original deployment was duly audited, this attack vector had not been identified in the original audit reports. Now, with the Hacken audit in place, an external, public review of the code underpins the next chapter of the ecosystem.
With audited contracts in hand and a community mandate behind them, the path to recovery began.



