OAK — OnChain Attack Knowledge

Worked example · 2020-09

SushiSwap dev-fund T5.005 + vampire-attack launch — Ethereum — 2020-08-26 to 2020-09-11

Loss
approximately $14M nominal (~38,000 ETH-equivalent at the early-September 2020 mark) extracted from the SushiSwap developer fund — the 10% of SUSHI emissions allocated to the project's development team — by pseudonymous founder "Chef Nomi" via on-chain swap of the dev-allocated SUSHI into ETH against SushiSwap's own pools on 2020-09-05; Chef Nomi subsequently returned the entire $14M to the SushiSwap multisig treasury on 2020-09-11, six days later. Realised user-side loss was the SUSHI market-price collapse of approximately 73% during the post-dump window, which represented a multi-hundred-million-dollar mark-to-market drawdown for SUSHI holders even after the fund return. The case is therefore best characterised as a near-rug returned rather than a completed rug, and is the canonical T5.005-with-recovery worked example on the public record.
OAK Techniques observed
OAK-T5.005 (Treasury-Management Exit — primary; the dev-fund swap was substantively divergent from the public framing under which the dev-allocation had been stewarded — Chef Nomi had repeatedly publicly committed to not selling the dev-allocation in the launch communications) + OAK-T2.001 (Single-Sided Liquidity Plant — composing primitive: SushiSwap's own LP pools were the venue against which the dev-fund was monetised; the dump occurred during the period before the LP migration completed, when Sushi's pools were still being seeded by community LPs) + OAK-T1.004 (Concentrated Supply at Genesis — the 10% dev-fund allocation of SUSHI emissions was a concentrated-supply-at-genesis mechanism controlled by Chef Nomi; the vampire-attack launch mechanic — a deliberate liquidity-draining campaign against Uniswap that converted approximately 55% of Uniswap's liquidity to SushiSwap-controlled liquidity within days — was the aggressive and unusual bootstrapping substrate for the 2020 era). T1.005 / T1.001 (transfer-restriction primitives) do not apply: SUSHI's contract was not honeypotted; the failure was operator-side stewardship of the dev-fund, not contract-layer trap.
Attribution
pseudonymous at the time (Chef Nomi self-identified only via the pseudonymous handle and a public-facing Twitter account); subsequent partial de-pseudonymisation to a Japan-based individual was published in industry coverage in 2021-2022 but has not been formally confirmed via legal filing or operator-side disclosure. The handover of the multisig keys to FTX-then-CEO Sam Bankman-Fried on 2020-09-06 — between the dump and the return — produced a separate and complicated post-incident attribution layer that runs through the FTX collapse two years later.
Key teaching point
**SushiSwap September 2020 is the cleanest worked example of a T5.005 case that was *returned*** — distinct from the "completed-rug-with-zero-recovery" canonical T5.005 shape (SafeMoon, Polywhale) and from the "regulator-action-after-the-fact" shape (SafeMoon SEC charges 2023). The case demonstrates that public-pressure-mediated recovery is a real T5.005 recovery channel, but it is not contract-layer-enforceable — Chef Nomi could have ignored the public pressure indefinitely. The case is also the canonical 2020 anchor for the T1 + T2.001 + T5.005 launch-mechanic chain and the v0.1 OAK reference for the vampire-attack token-genesis sub-shape.

Summary

SushiSwap launched on 2020-08-26 as an Ethereum-based decentralised exchange built on a hard fork of Uniswap V2's open-source contract code, with a vampire-attack bootstrapping mechanic: users were incentivised to deposit their Uniswap LP tokens into SushiSwap's MasterChef staking contract, where they earned SUSHI emissions on top of their existing Uniswap LP fees; on a scheduled migration date, the deposited Uniswap LP tokens would be redeemed against Uniswap's pools and the underlying tokens migrated to seed SushiSwap's own pools. The mechanic worked: within days of launch, more than $1B in Uniswap LP tokens had been deposited into SushiSwap's MasterChef, representing approximately 55% of Uniswap's total locked liquidity at the time. The launch was anonymously developed by an account self-identified only as "Chef Nomi" with two collaborators ("0xMaki" and "sushiswap"), and the project's public framing centred on the explicit promise that the 10% developer-allocation of SUSHI emissions would not be sold to fund individual development team profits — a framing Chef Nomi reiterated in multiple public communications during the launch window.

On 2020-09-05, between the launch and the scheduled migration, Chef Nomi swapped the developer-fund SUSHI allocation into approximately 38,000 ETH (~$14M at the timestamp) against SushiSwap's own pools and the broader DeFi-aggregator routing surface. The swap was on-chain visible in real time and produced an immediate ~73% collapse in the SUSHI market price as the community recognised the substantive divergence from the public framing. The community response was sharp and immediate: prominent DeFi figures (including Vitalik Buterin) called the action an exit-scam; the broader DeFi community pressured Chef Nomi to return the funds; FTX-then-CEO Sam Bankman-Fried offered to take over the multisig keys to ensure the migration completed safely. On 2020-09-06, Chef Nomi handed the multisig keys to Bankman-Fried; the migration completed under SBF's stewardship over the next several days. On 2020-09-11, Chef Nomi posted a public apology ("I f**ked up. And I am sorry.") and returned the entire 38,000 ETH ($14M) to the SushiSwap multisig treasury. The community subsequently voted (under SBF's interim stewardship) to retain SBF / FTX as the multisig signer cohort and to continue protocol operations; SushiSwap survived, the migration completed, and the protocol entered the standard top-tier-DeFi protocol operating pattern. SUSHI's price recovered partially but did not return to pre-dump levels for several months.

The case is structurally ambiguous between completed-rug-then-returned and near-rug-prevented-by-public-pressure. The T5.005 framing (substantive misuse of the dev-fund relative to its public framing) is unambiguous: the dev-fund was swapped for ETH for individual operator benefit, in direct contradiction of the public commitment. The recovery channel (public-pressure-mediated voluntary return) is also unambiguous as a T5.005 outcome category. The downstream complications (SBF / FTX involvement; the FTX collapse 2022-11; the multisig handover lineage) are out of scope for the T5.005 mapping but are documented in the timeline for completeness.

Timeline (UTC)

When Event OAK ref
2020-08-26 SushiSwap launches; vampire-attack mechanic begins; Uniswap LP-token deposits into MasterChef contract begin T1 (Token Genesis — vampire-attack sub-shape)
2020-08-26 to 2020-09-05 Vampire-attack accumulates >$1B in Uniswap LP-tokens (~55% of Uniswap's locked liquidity); launch communications include explicit Chef Nomi commitment that the 10% dev-fund allocation will not be sold T1 (T2.001 LP setup)
2020-09-05 Chef Nomi swaps 10% dev-fund SUSHI allocation for 38,000 ETH ($14M) on-chain against SushiSwap and broader DeFi-aggregator routing T5.005 dev-fund extraction
2020-09-05 (post-swap, hours-window) SUSHI market price collapses ~73%; community recognises swap event; broader DeFi community publishes commentary framing the action as an exit-scam (defender response — community-recognition signal)
2020-09-05 to 2020-09-06 Sam Bankman-Fried publicly offers to take over the multisig keys to ensure migration completes; Chef Nomi accepts (operator response — interim stewardship transfer)
2020-09-06 Chef Nomi hands multisig keys to Sam Bankman-Fried (operator response)
2020-09-06 to 2020-09-09 Migration completes under SBF stewardship; vampire-attack-deposited Uniswap LP-tokens redeemed against Uniswap pools; underlying tokens migrated to seed SushiSwap pools T1 (vampire-attack completion; T2.001 SushiSwap pool seeding)
2020-09-11 Chef Nomi posts public apology and returns 38,000 ETH ($14M) to SushiSwap multisig treasury T5.005 voluntary-return recovery channel
2020-09-11 onward Community vote (under SBF's interim stewardship) to retain SBF / FTX as multisig signer cohort; protocol continues operations (post-event governance)
2022-11-08 onward FTX collapse; SushiSwap multisig signer-set composition becomes a separate post-FTX-collapse audit subject (out of T5.005 scope; included for downstream-context completeness) (cohort context)

What defenders observed

  • Pre-event (token-genesis layer — vampire-attack as T1 sub-shape): SushiSwap's launch mechanic was the canonical vampire-attack: a deliberate liquidity-draining campaign against Uniswap that converted ~55% of Uniswap's locked liquidity to SushiSwap-controlled liquidity within days. The mechanic was novel for the 2020 era and produced an aggressive and unusual launch-mechanic surface that future Sushi-clone launches replicated through 2021-2022. Defender-side observation: vampire-attack launches are operationally legitimate (no contract-layer trap) but produce a concentration risk at the launching protocol's operator-side that is not captured by standard token-launch checklists. SushiSwap's 10% dev-fund allocation, established at genesis, was the load-bearing T5.005 surface.
  • Pre-event (operator-side commitment layer): Chef Nomi's pre-event public framing explicitly committed to not selling the dev-fund. This commitment was operator-side-promised rather than contract-layer-enforced — there was no smart-contract restriction that prevented the swap. The defender-side observation here is the canonical T5.005 indicator: operator-side commitment that is not contract-layer-enforced is not contract-layer-enforceable. The same observation applies across the SafeMoon, Polywhale, and broader soft-rug cohort: operator promises about treasury / dev-fund stewardship are governance-layer commitments at best, and require either community-controlled multisig or DAO-controlled stewardship to be enforceable.
  • At-event (real-time on-chain signal): the dev-fund swap was on-chain visible in real time. A defender-side dev-fund-monitoring detector — alerting on any swap of pre-event-allocated dev-fund tokens — would have produced a signal in the same block. Twitter-driven community recognition produced the signal in practice within hours; the lag between on-chain event and broad community recognition was approximately 1-2 hours.
  • At-event (multisig-handover layer — separate operational exposure): the handover of the multisig keys to SBF was a separate operational exposure that was not load-bearing for the T5.005 outcome but became material 26 months later when FTX collapsed. The handover demonstrated that interim stewardship transfer is a real recovery-channel category for protocols whose operator-side has demonstrably violated their commitments — but the recovery channel introduces a new operational exposure (interim steward's own integrity / continuity), and that exposure became material at the FTX collapse boundary. Future T5.005 contributions documenting interim-stewardship recovery should track the interim-steward's continuity as a discrete cohort variable.
  • Post-event (voluntary-return recovery channel): Chef Nomi's voluntary return of the $14M is the canonical T5.005 public-pressure-mediated voluntary-return recovery channel. The recovery was not contract-layer-enforceable, was not regulator-mediated, and was not operationally guaranteed; it was the outcome of public-pressure escalation through the DeFi community and (uniquely here) through prominent community figures including Vitalik Buterin. Future T5.005 contributions should track this recovery channel separately from regulator-mediated recovery (SafeMoon SEC charges) and from operator-funded reimbursement (Vee Finance compensation pool).

What this example tells contributors writing future Technique pages

  • T1 has a vampire-attack sub-shape distinct from honeypot, modifiable-tax, and renounced-but-not-really sub-shapes. SushiSwap is the canonical 2020 anchor for the vampire-attack token-genesis sub-shape and pairs with the broader fork-substrate-vulnerability meta-class observation: vampire-attacks are operationally legitimate at the contract layer (no honeypot, no transfer restriction) but produce a concentration-risk profile at the operator-side that future T1 contributions documenting Sushi-clone or aggressive-vampire-launch protocols should explicitly track.
  • T5.005 has a public-pressure-mediated voluntary-return recovery channel distinct from regulator-mediated and operator-funded-reimbursement channels. The full T5.005 recovery-channel taxonomy now reads: (a) zero recovery (Polywhale, broader soft-rug cohort), (b) regulator-mediated recovery (SafeMoon SEC complaint as the canonical regulator-side anchor), (c) operator-funded reimbursement (Vee Finance compensation pool, bZx), (d) public-pressure-mediated voluntary return (SushiSwap), (e) interim-stewardship recovery (SushiSwap's SBF-handover sub-channel, with the cautionary note that interim-steward continuity is itself a new operational exposure). Future T5.005 contributions should map each new case to one of these categories explicitly.
  • Operator-side commitment that is not contract-layer-enforced is not contract-layer-enforceable. The Chef Nomi pre-event commitment to not sell the dev-fund had no on-chain enforcement; the swap was operationally trivial. Future T5.005 contributions documenting operator-side promises about treasury / dev-fund stewardship should explicitly note whether the promise is contract-layer-enforced (DAO-controlled multisig, time-locked treasury, vesting cliff) or operator-promised (Twitter / Discord / governance-blog statements without on-chain enforcement). The two have categorically different defender-relevant interpretations.
  • The downstream-context observation (FTX 2022) is a separate concern from the immediate T5.005 outcome. The SushiSwap → SBF multisig handover was a recovery-channel mechanism for the immediate September 2020 incident; it became a separate operational exposure 26 months later when FTX collapsed. Future T5.005 / T11.x contributions should treat downstream-context exposures as cohort observations rather than as load-bearing for the originating T5.005 mapping.

Public references

Citations

  • [coindesksushichefnomi2020] — primary contemporaneous press; $14M / 38,000 ETH return figure.
  • [thedefiantsushichefnomi2020] — contemporaneous press; public-apology framing.
  • [theblocksushichefnomi2020] — contemporaneous press; 38,000 ETH figure.
  • [decryptsushichefnomi2020] — contemporaneous press; timeline.
  • [cointelegraphsushichefnomi2020] — contemporaneous press; consolidated return event.
  • [defiratesushichefnomi2020] — community-side analysis; SUSHI 73% price-collapse figure.
  • [finematicsvampireattack] — retrospective educational; vampire-attack mechanic walkthrough.
  • [geminisushivampire] — retrospective educational; vampire-attack class context.
  • [zhou2023sok] — academic taxonomy classifying T5.005-class operator-side fund-misuse cases.

Discussion

SushiSwap September 2020 is the canonical 2020 anchor for the T1 + T2.001 + T5.005 launch-mechanic chain and the cleanest worked example of a T5.005 case that was returned. The structural lesson is that operator-side commitment that is not contract-layer-enforced is not contract-layer-enforceable, and the recovery channel that produced the $14M return (public-pressure-mediated voluntary return, escalated through prominent community figures and amplified by interim-stewardship transfer) is real but is not contract-layer-guaranteed. Future T5.005 contributions documenting operator-side promises should explicitly distinguish contract-layer-enforced commitments (DAO-controlled multisig, time-locked treasury, vesting cliff) from operator-promised commitments (Twitter / Discord / governance-blog statements without on-chain enforcement) — the two have categorically different defender-relevant interpretations.

The case anchors the vampire-attack token-genesis sub-shape within T1 and pairs with the broader fork-substrate-vulnerability meta-class observation we documented at TSD March 2021 (examples/2021-03-true-seigniorage-dollar.md), Curio March 2024 (examples/2024-03-curio.md), and the Hundred → Midas → Sonne → Onyx Compound-v2-fork rounding-error cohort. SushiSwap was a Uniswap-V2 fork; the launch mechanic was a deliberate aggressive bootstrapping of the fork against the parent; the operator-side commitment (no dev-fund sell) was the load-bearing T5.005 surface that the fork-substrate did not carry forward as a contract-layer constraint. The pattern recurs: forks inherit the parent's contract-layer protections but do not inherit the parent's operator-side practices — a recurring meta-class observation across T1, T5.005, T9.003, and T16.

The downstream-context layer (the SBF / FTX multisig handover lineage and its 26-month-later collapse) is out of scope for the T5.005 mapping but is documented in the timeline for completeness. Future T5.005 / T11.x contributions documenting interim-stewardship recovery should track the interim-steward's continuity as a discrete cohort variable, with the cautionary note that interim-stewardship recovery introduces a new operational exposure that may become material on a multi-year timescale. The SushiSwap → SBF multisig handover demonstrated both the recovery-channel utility and the new-exposure dimension within a single case — a useful teaching observation for contributors writing about recovery-channel design.

Attribution-strength is pseudonymous — Chef Nomi's identity has been partially de-pseudonymised in industry coverage to a Japan-based individual but has not been confirmed via legal filing or formal operator-side disclosure. The cohort-level OAK observation that pseudonymous T5.005 attackers tend to operate at smaller dollar-magnitude than named / indicted T5.005 attackers does not hold here: SushiSwap's $14M is between TSD's $16.6K and Mango Markets' $47M, but the recovery channel (voluntary return) means the realised user-side loss was the SUSHI mark-to-market drawdown rather than the $14M extraction. The realised-vs-nominal-vs-recovered loss measure for SushiSwap therefore differs from any case in the broader T5.005 cohort and is the cleanest single-case worked example of why T5.005 contributions should report all three loss measures (nominal extraction, realised post-monetisation, post-recovery user-side outcome) as separate calibration variables.

Techniques demonstrated (3)