Addresses associated with the Euler Finance exploiter returned 58,737.25 ETH to the lending protocol on March 25, 2023, providing the first evidence that a substantial portion of the assets taken in a roughly $197 million exploit might be recovered.
Ethereum recorded the larger transfer at 15:08:23 UTC, when an address publicly labeled Euler Finance Exploiter 2 sent 51,000 ETH directly to Euler’s deployer address. A second transaction at 15:38:11 UTC routed 7,737.25 ETH from an intermediary address to the same destination. Together, the transfers were worth approximately $102.4 million using Etherscan’s historical reference price of $1,743.88 per ETH for the first transaction.
That dollar figure is a calculation, not verified cash proceeds: 58,737.25 ETH multiplied by the explorer’s reference price. Ether traded continuously across venues, and the value would differ with the exchange, timestamp and execution assumptions selected. Contemporaneous reporting rounded the combined value to approximately $102 million.
A recovery, not a resolution
The March 25 transfers did not establish that all affected users would be repaid. They moved ether into an address controlled by the Euler system, but a complete restoration still depended on recovering the remaining assets, reconciling protocol liabilities and adopting a distribution plan.
They nevertheless changed the event-day evidence. Before March 25, the protocol faced a large insolvency following its March 13 exploit, while the attacker’s intentions remained uncertain. A previous 3,000 ETH had been returned on March 18, but the 51,000 ETH direct payment was much larger and represented close to half of the approximately $197 million event-time loss estimate by itself.
The transfer also demonstrated a distinctive feature of public-blockchain incident response. Observers did not need to rely solely on a private negotiation or company statement to see that funds had moved. The sending addresses, receiving address, quantities, block timestamps and successful transaction status were publicly inspectable. The attribution of an address to the exploiter and another to Euler still depended on transaction history, public labels and corroborating investigations rather than an identity field embedded in Ethereum.
What caused the original loss
Security researchers attributed the March 13 exploit to a missing account-health check around Euler’s `donateToReserves()` function. The attacker used flash-borrowed assets to create a highly leveraged position, donated collateral to reserves until the position became eligible for liquidation, then self-liquidated and withdrew assets from multiple pools.
CertiK’s contemporaneous analysis estimated that the attack removed 8.88 million DAI, 8,080 wrapped ether, 846.4 wrapped bitcoin, 73,821 staked ether and 34.22 million USDC. The firm estimated a total loss of approximately $197 million and reported that subsequent swaps left attacker-associated wallets controlling about 96,732.66 ETH and approximately 43 million DAI. Those are security-firm estimates derived from an on-chain reconstruction, not an audited final accounting.
The incident mattered beyond Euler because other decentralized-finance applications had deposited assets into the protocol or relied on its liquidity. A failure in one lending system could therefore impair treasuries, stablecoin arrangements and yield products elsewhere. The March 25 return reduced the apparent shortfall but did not erase the underlying smart-contract and dependency risks.
Later clarification
On April 4, 2023, the Euler Foundation announced that negotiations had resulted in the return of all recoverable funds. That later outcome confirms that March 25 became a major step in a broader recovery, but it was not knowable from the two transfers alone. On March 25, the defensible conclusion was narrower: approximately $102.4 million in ether had returned, while the final recovery and user-restoration process remained unresolved.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

