Ethereum's ERC777 token standard faces scrutiny after $25M Open Finance exploits

Quick Take
- The attacks on Open Finance protocols Lendf.Me and Uniswap last weekend triggered some scrutiny of the ERC777 token standard
- The attackers were able to initiate reentrancy attacks on protocols that supported ERC777 tokens but did not have reentrancy protection
- Despite the vulnerability, ERC777 may offer more advantages over ERC20 in the DeFi context
We'd love your feedback.
Who's to blame for the $25.3 million losses in the two imBTC attacks?
Sure, as Open Finance lending protocol Lendf.Me CEO Mindao Yang admitted, the attack was his failure because he should have "anticipated it and take actions to prevent it." However, since the attackers exploited the same vulnerability of the ERC777 token standard on both decentralized exchange Uniswap and Lendf.Me, some people are turning their attention to the token standard itself.
"I do have a fear that people will think ERC777 equals not safe. And I don't think that's really totally fair," said decentralized lottery protocol PoolTogether CEO Leighton Cusack.
What led to one of the biggest losses in the history of Open Finance – although all of the lost funds has been returned by the hackers – was, in fact, a well-known scheme called the reentrancy attack.
The ERC777 token standard supports token transfer functions that can be called repeatedly to move funds from one address to another without updating the account balance. As such, the attackers were able to drain imBTC – an ERC777 token – from both Uniswap Version 1 and Lendf.Me, neither of which has the mechanism in place to prevent reentrancy.
ERC777 was known to have the reentrancy problem on some Open Finance platforms, a point that was discussed in depth in a ConsenSys audit of Uniswap released over a year ago. As Cusack put it, this vulnerability would be the first thing an auditor notices when checking a protocol.
"This vulnerability, from an auditor's perspective, is very trivial," he said.
Now, the two attacks have brought ERC777 to the front and center of social media discussions and some Open Finance developers, such as PieDAO CTO Dan Matthews, worry that the negative image this standard has become associated with may hinder its adoption.
"I do think there will be an impact on the adoption of the standard, but I expect that to be temporary. PieDAO PIEs are fully compatible with ERC777. We have no plans to back away from their use," Matthews told The Block.
Instead of a less secure token standard, ERC777 was in fact devised as an improvement of ERC20 while having backward compatibility with the latter. As a more flexible token standard, ERC777 allows hooks or functions that enable contracts and regular addresses to control and reject tokens they send and receive.
"I would say the ERC777 standard improves the way that tokens can interact with smart contracts… It is a step forward. But it does have a different risk profile than the ERC20. And a lot of times a lot of these DeFi things are built for ERC20 and they're not built for the ERC777," said Cusack.
Indeed, by itself, ERC777 tokens are not vulnerable to the reentrancy attack. However, when they are used in combination with certain protocols, hackers are able to trigger certain fund transfer functions to drain the funds.
As such, other Open Finance protocols also came under scrutiny. Balancer Labs confirmed on Twitter that they have reentrancy protection. Kyber Network seems to have a similar mechanism in place, according to its Github.
Bancor, on the other hand, has a long history of writing allegedly "flawed" code, and the team brushed off reentrancy concerns in 2017. Uniswap's version 2 also addressed this problem, although version 1 cannot be updated by design.
Meanwhile, soon after the attacks happened, PoolTogether removed around 500 plDAI, also an ERC777 token, from an Uniswap liquidity pool set up for third-party developers with the company's own funds. PieDAO, a protocol that generates BTC++ tokens – representing a basket of BTC-pegged tokens on Ethereum, including imBTC – also paused trading to prevent any stolen imBTC from flowing into their pool and added a cap for the total BTC++ supply.
It is perhaps worth noting that although ERC777 token holders are advised to move their assets off Uniswap as a precaution, users who are not so tech-savvy can't easily tell ERC20 apart from ERC777. On Etherscan, both ERC777 and ERC20 are marked as ERC20 tokens. To check which standard a token is using, users may have to go through the token issuers' Github.
"My own opinion is that as an industry, we cannot expect users to fully understand the risks of platforms in which they are staking their funds. We must do a better job of warning them of these risks and proactively identifying when they don't heed these warnings," said Matthews.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

