SIR.trading
Summary
SIR.trading (Synthetics Implemented Right) is an Ethereum-based DeFi protocol launched on February 20, 2025, offering leveraged trading without liquidation risk or volatility decay. On March 30, 2025, an attacker exploited a transient storage vulnerability in the protocol's Vault contract to drain the entire $355,000 TVL — one of the first documented real-world exploits targeting Ethereum's EIP-1153 transient storage feature introduced in the Dencun upgrade. The protocol subsequently relaunched after completing additional security audits, but no stolen funds were recovered.
Connected Entities
1 entities · 10 linked investigationsTimeline(8 events)
2021-01-01
Pseudonymous founder Xatarrer begins developing SIR.trading over approximately four years without venture capital funding, supported by approximately $70,000 from community contributors.
Rekt News2025-01-01
Egis Security completes security audit of SIR.trading, finding 3 high-severity, 2 medium-severity, and 2 low-severity issues. The transient storage slot collision vulnerability is not identified.
Rekt News / GitHub Egis-Security2025-01-30
Attacker deploys malicious ERC-20 tokens and creates a controlled Uniswap V3 liquidity pool, beginning preparation for the exploit at 6:18 UTC.
Blockscope Research2025-02-20
SIR.trading launches on Ethereum mainnet, growing to approximately $355,000–$400,000 TVL through organic growth without advertising.
Rekt News2025-03-30
Attacker exploits transient storage slot collision in the Vault contract's uniswapV3SwapCallback function, draining the entire $355,000 TVL in USDC, wBTC, and wETH. Stolen assets are immediately routed through Railgun. The exploit is detected by TenArmorAlert and Decurity.
CoinTelegraph2025-03-31
Founder Xatarrer issues on-chain plea to the attacker, offering $100,000 bounty to keep as compensation for the bug discovery and requesting the return of the remaining ~$255,000, pledging no legal action. Describes the event as 'the worst news a protocol can receive.'
Crypto.news2025-04-01
Attacker does not respond to bounty offer. Stolen funds remain in Railgun. SIR team announces intent to relaunch and begins seeking auditors willing to accept token equity in lieu of payment.
Rekt News2025-01-01
Protocol relaunches at app.sir.trading following completion of four independent security audits. No stolen funds recovered. Relaunch expands to HyperEVM and MegaETH networks in addition to Ethereum.
SIR Official DocumentationDecision Log
- hash: nBZ8aRNPEanGzmTKfCGfRxGEHaadug2Nj6YAY7MWaan
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 6/1/2026, 5:49:20 PM
last updated: 6/1/2026, 5:49:24 PM
avoid.net — verified advice for a post-truth world