The Velocore decentralized exchange was exploited on June 2, 2024, prompting Linea’s operators to halt the network’s sequencer and censor attacker addresses while the protocol investigated. Velocore estimated that approximately $6.8 million of assets was lost from its volatile liquidity pools across Linea and zkSync Era.

The incident mattered beyond the affected exchange. It demonstrated how a fault in application-level smart contracts could trigger an intervention at the network level—and how an Ethereum layer-two operator could suspend transaction processing despite describing its long-term objective as a permissionless, censorship-resistant system.

What Velocore reported

Velocore said its constant-product market-maker pools, identified as CPMM pools, were affected on Linea and zkSync Era. Its stable pools were not affected. The team attributed the incident to flawed logic in its Balancer-style CPMM contracts and said it was working with security teams, exchanges and the relevant networks.

Contemporaneous reporting placed the loss at approximately $6.8 million, although initial reports circulated estimates near $10 million. The lower figure came from Velocore’s post-incident assessment and was subsequently adopted by DefiLlama and independent security analyses. It should be treated as an incident estimate rather than an audited loss statement: Velocore did not disclose the precise asset-pricing timestamp, exchange inputs or dollar-conversion methodology used to calculate it.

Recorded attack transactions show the affected contracts being called on Linea, while a separate transaction was identified on zkSync Era. Later technical analysis found that the attacker could call Velocore’s `velocore__execute` function without the expected caller restriction, manipulate a fee multiplier and trigger faulty arithmetic during a single-token withdrawal. That explanation was developed from contract traces and code analysis after June 2; on the event date, the verified facts were that the volatile pools had been drained and the protocol had identified a contract-logic vulnerability.

Why Linea stopped the sequencer

Linea said its monitoring partners detected the exploit while Velocore remained vulnerable and the network team could not reach Velocore’s operators. According to Linea, 700 ETH had already moved off the network through a third-party bridge. The 700 ETH figure describes the amount Linea reported bridged from its network, not the entire cross-chain loss and not a dollar valuation.

Linea then paused its sequencer between blocks 5,081,800 and 5,081,801. A sequencer orders and submits layer-two transactions; stopping it interrupted normal block production. Linea also said it censored addresses associated with the attacker and used the pause to give Velocore time to investigate the vulnerability.

The intervention did not reverse the completed exploit, and Linea did not claim that all funds had been preserved. Its stated objective was to prevent additional assets from leaving the network and limit wider disruption as the attacker converted other tokens into ether.

Protection and centralization

Linea characterized the halt as a last-resort safeguard available while the network remained in an early operational stage. It simultaneously acknowledged that a mature, decentralized sequencer should remove the team’s ability to stop block production or censor addresses.

That trade-off was the institutional significance of June 2. Centralized control allowed an operator to respond quickly to an application failure, but the same authority meant users could not assume uninterrupted, censorship-resistant transaction ordering. The exploit therefore exposed two distinct risks: vulnerable DeFi contracts could misdirect deposited assets, and the surrounding layer-two infrastructure still depended on discretionary operator controls.

Velocore’s affected-pool boundaries, Linea’s block interval and the identified attack transactions are well supported. The final recoverable loss, compensation available to liquidity providers and effectiveness of the sequencer intervention were unresolved on June 2, 2024.

Primary sourceLinea — June 2, 2024 Velocore incident statement

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.