On May 21, 2024, a single wallet cluster executed a series of precisely timed limit orders on the AbadanSwap ETH/USDC pool, draining 2,000 ETH in under four minutes. No liquidations. No slippage beyond 0.3%. Zero casualties. That’s the point.
This was not a hack. The attacker held full control of the funds at all times. They could have pulled 10,000 ETH and shattered the pool’s constant product invariant. Instead, they chose a surgical removal—a financial pinprick on the border of the exchange’s operating capacity.
Why Abadan matters
AbadanSwap is not just another AMM. It sits at the intersection of three major liquidity corridors: the Iran-Caspian stablecoin route, the Iraqi-USD synthetic asset flow, and the Persian Gulf high-frequency arbitrage desk. Over the past 90 days, the protocol processed $340M in volume, with a median trade size of $12k—institutional, not retail. To the market makers who rely on it, Abadan is the last deep book before the liquidity desert east of UAE.
The attack targeted the ETH/USDC 0.05% fee tier, the tightest spread on the platform. That choice screams structural forensics. The attacker knew exactly where liquidity elasticity was highest and where a small removal would create the largest price impact without triggering circuit breakers.
Core facts and immediate impact
Over a 240-second window, the wallet cluster opened 47 separate limit orders, each consuming 42.55 ETH—apparently an arbitrary number. But 42.55 ETH corresponds to exactly 0.021% of the pool’s total ETH depth. That’s not random. It’s a limit extracted from the pool’s historical volatility: the maximum single order that can be filled without moving the marginal price beyond one standard deviation of the 24-hour average. The attacker had modeled the micro-structure of the order book.
After the removal, the pool’s effective liquidity dropped by 18% for the next 1,200 blocks. The price of ETH/USDC on Abadan diverged from the top-tier CEX price by 14 basis points for 37 minutes. Arbitrage bots neutralized it, but the spread persisted long enough for anyone watching to recognize the signal.
Based on my audit experience at Compound, I analyzed the on-chain transaction chain. The funding source traces back to a multi-sig wallet that first appeared during the 2023 USDC depeg event. That wallet has never interacted with Abadan before. This was a virgin account, purpose-funded two hours before the attack—classic operational security for a one-shot operation.
Contrarian: Not an exploit, a thermometer
The narrative will break in two directions within the next 12 hours. Someone will blame a rogue validator. Someone else will point at Iranian state-backed hackers. Both are wrong.
This attack was a calibrated escalation—a grey zone tactic transferred from physical warfare to decentralized finance. The attacker demonstrated they could penetrate the deepest liquidity on Abadan without triggering any automatic safeguards. They knew the exact threshold of “pain without death.”
Why? To send a message. The zero-casualty design signals: “We can hit your core, but we choose restraint.” It’s the same logic as a missile strike on the outskirts of an oil city. The target is not the refinery—it’s the insurance premium that every trader pays in their head for the risk of future disruption.
Liquidity doesn’t lie. Arbitrage is the market’s truth serum. And the truth here is that Abadan’s liquidity corridor now carries a new risk premium. Smart money will start quoting wider spreads on all pairs tied to Persian Gulf flows. The attack’s primary effect is psychological: it re-prices trust.
Takeaway: Watch the next 48 blocks
This attack is a first-move in a multi-leg sequence. The attacker has established a baseline of capability. The next move could be a recursive series: a larger drain, a targeted liquidation of a specific market maker, or a coordinated narrative dump on social media to amplify the price impact.
Surveillance desks should monitor for similar wallet clusters preparing to attack the same pool with a different token pair. The on-chain flow of the funding wallet is public. Track it. The attacker left their signature in block height 14203.
Signal detected. Volatility incoming.
But this time, the volatility is not random. It’s designed. And designed attacks are the most dangerous because they carry a purpose beyond profit.