
SushiSwap
SushiSwap is a decentralized exchange that began in 2020 as a community-run fork of Uniswap. Like other automated market makers, it lets anyone swap tokens directly from their own wallet against liquidity pools, with prices set by a formula instead of an order book. It launched with a headline-grabbing "vampire attack" that pulled liquidity away from Uniswap, is governed and rewarded through its SUSHI token, and has since grown into a multichain protocol running on dozens of networks. Because it is non-custodial and permissionless, it carries the scam-token and phishing risks common to every DEX, and its router was exploited once, in 2023.
- Launched
- August 2020 as a Uniswap fork by the pseudonymous "Chef Nomi"2020-08 · source
- Model
- Non-custodial automated market maker (AMM); you trade from your own wallet
- Reach
- Multichain, operating across dozens of blockchains
- Token
- SUSHI (governance, staking and rewards)
What is SushiSwap?
SushiSwap is a decentralized exchange (DEX) built on the automated market maker (AMM) model. Rather than matching buyers and sellers through an order book, it lets liquidity providers deposit pairs of tokens into pools, and traders swap against those pools at prices set by a formula. It is non-custodial and permissionless, so you trade directly from your own wallet and no company holds your funds.
It launched in August 2020 as a near-verbatim fork of Uniswap's code by a pseudonymous developer known as Chef Nomi, adding a governance token — SUSHI — that Uniswap did not yet have. Its debut is remembered for a "vampire attack": SushiSwap rewarded users who staked Uniswap liquidity tokens with SUSHI, then migrated that liquidity onto its own contracts. Since then it has become a community-governed, multichain protocol running across dozens of networks, with SUSHI used for governance, staking and rewards.
Is SushiSwap safe?
SushiSwap is non-custodial, so no company vault holds your funds, and its core AMM pools have handled large volume since 2020. But its record is not spotless: a peripheral contract has been exploited, so it is worth understanding what happened.
In April 2023 its RouteProcessor2 router — a trade-routing contract deployed only days earlier — contained an approval bug: it failed to validate the route parameter, letting an attacker redirect swaps through an attacker-controlled pool and drain tokens from users who had granted the new router an allowance. About $3.3 million was taken. This affected the router, not the underlying liquidity pools, and recovery was partial: white-hat efforts and a claims portal returned a substantial share of the funds, but not all of it. The other risks are the ones inherent to any DEX: permissionless listing means scam and "honeypot" tokens exist, and phishing sites or malicious approval prompts can drain a wallet. A practical lesson from the 2023 event is to periodically review and revoke token approvals, confirm the official domain, and read what you sign.
Incident record
On 9 April 2023 SushiSwap's RouteProcessor2 router — deployed only days earlier — was exploited because it did not validate the route parameter passed to its processRoute function, letting an attacker redirect swaps through an attacker-controlled pool and drain tokens from users who had approved the new router. About $3.3 million was taken, including roughly 1,800 ETH from a single user. The underlying AMM pools were not drained. Recovery was partial: white-hat efforts recovered over 1,000 ETH and SushiSwap opened a claims portal, but not all funds were returned. Recorded as partial.
Compare with
Frequently asked
Is SushiSwap safe?+
SushiSwap is non-custodial, so no company holds your funds, and its core AMM pools have run since 2020 without being drained. But its record is not spotless: in April 2023 its RouteProcessor2 router had an approval bug that let an attacker drain about $3.3 million from users who had approved it, with only partial recovery. The usual DEX risks also apply: scam tokens and phishing. Review your token approvals and confirm the official domain.
What is SushiSwap?+
SushiSwap is a decentralized exchange that launched in August 2020 as a community-run fork of Uniswap. It is a non-custodial automated market maker: you swap tokens directly from your own wallet against liquidity pools, and its SUSHI token is used for governance, staking and rewards. It now runs across dozens of blockchains.
Was SushiSwap hacked?+
Its core liquidity pools have not been drained, but a peripheral contract was exploited. In April 2023 its newly deployed RouteProcessor2 router had a missing-validation bug that let an attacker take about $3.3 million from users who had approved it. Recovery was partial through white-hat efforts and a claims portal.
How is SushiSwap different from Uniswap?+
SushiSwap began in 2020 as a fork of Uniswap's code, adding the SUSHI governance token and community ownership from the start. It launched with a "vampire attack" that drew liquidity away from Uniswap. Both are non-custodial AMMs, but SushiSwap has emphasized multichain reach and community governance.
What changed
- 2026-09-28Profile created: SushiSwap the community-run Uniswap fork and multichain AMM, its SUSHI token, and the April 2023 RouteProcessor2 approval-bug exploit recorded as partial recovery.