USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. USPD disclosed the incident on Dec. 5, saying the exploit…USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. USPD disclosed the incident on Dec. 5, saying the exploit…

Decentralized stablecoin protocol USPD hit by $1M exploit

2025/12/05 15:14

USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds.

Summary
  • USPD suffered an exploit after an attacker seized proxy admin rights during deployment.
  • The breach led to unauthorized USPD minting and stETH outflows worth about $1 million.
  • The incident adds to a month of major exploits affecting exchanges and decentralized finance protocols.

USPD disclosed the incident on Dec. 5, saying the exploit allowed an attacker to mint roughly 98 million USPD and remove about 232 stETH, worth around $1 million. The team urged users not to buy the token and to revoke approvals until further notice.

Attackers used hidden proxy control 

The protocol stressed that its audited smart contract logic was not the source of the failure. USPD said firms such as Nethermind and Resonance had reviewed the code, and internal tests confirmed expected behavior. Instead, the breach came from what the team described as a “CPIMP” attack, which is a tactic that targets the deployment window of a proxy contract.

According to USPD, the attacker front-ran the initialization process on Sept. 16 using a Multicall3 transaction. The attacker jumped in before the deployment script finished, grabbed admin access, and slipped in a hidden proxy implementation.

In order to keep the malicious setup hidden from users, auditors, and even Etherscan, that shadow version forwarded calls to the audited contract.

The camouflage worked because the attacker manipulated event data and spoofed storage slots so that block explorers displayed the legitimate implementation. This left the attacker in full control for months until they upgraded the proxy and executed the minting event that drained the protocol.

USPD said it is working with law enforcement, security researchers, and major exchanges to trace funds and halt further movement. The team has offered the attacker a chance to return 90% of the assets under a standard bug-bounty structure, saying it would treat the action as a whitehat recovery if the funds are sent back.

Exploit adds to a month of heavy

The USPD incident arrives during one of the another active periods for exploits this year, with losses across December already passing $100 million.

Upbit, one of South Korea’s largest exchanges, confirmed a $30 million breach tied to Lazarus Group earlier this week. Investigators say the attackers posed as internal administrators to obtain access, continuing a pattern that has pushed Lazarus-linked thefts above $1 billion this year.

Yearn Finance also faced an early-December exploit affecting its legacy yETH token contract. Attackers used a bug that allowed unlimited minting, producing trillions of tokens in one transaction and draining about $9 million in value.

The run of incidents highlights the rising sophistication in DeFi-focused attacks, particularly those that target proxy contracts, admin keys, and legacy systems. Security teams say interest is picking up around decentralized multi-party computation tools and hardened deployment frameworks as protocols look to reduce the impact of single-point failures.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Korea’s Woori Bank Displaying Bitcoin Price in Its Trading Room

Korea’s Woori Bank Displaying Bitcoin Price in Its Trading Room

The post Korea’s Woori Bank Displaying Bitcoin Price in Its Trading Room appeared on BitcoinEthereumNews.com. Key Notes Woori Bank makes a crucial statement by demonstrating Bitcoin prices in its Seoul dealing room. This marks further integration of TradFi and crypto and a significant advancement in the firm’s crypto push. Hana Financial Group and Dunamu signed an agreement to introduce blockchain technology to services such as overseas remittances. On Dec. 5, South Korean multinational financial institution Woori Bank announced that it had begun to display the prices of Bitcoin BTC $91 264 24h volatility: 2.3% Market cap: $1.82 T Vol. 24h: $44.61 B in its main trading room in Seoul. It included won-dollar exchange rates and stock market data alongside. Woori Bank Demonstrates Crypto Interest The trading room is a meeting place for market makers, where frontline trading of foreign exchange, bonds, and derivatives takes place. An official of the bank noted that the initiative is in response to the growing prominence of crypto. “As digital assets continue to grow in prominence and influence in global financial markets, we determined that they should be monitored as a key indicator to better read overall market trends,” the Woori Bank official stated. Interestingly, the financial ecosystem has been seeing a subtle push towards the integration of the Traditional Finance (TradFi) system and digital asset markets. There have been quite a number of alliances set to spark such integrations. Recently, American crypto exchange Kraken signed a strategic partnership deal with Deutsche Börse to bridge TradFi and crypto. Together, they intend to engage in trading, custody, settlement, collateral management, and tokenized assets. Similarly, Hana Financial Group and Dunamu signed an agreement recently to introduce blockchain technology to services such as overseas remittances. Woori Bank is yet to hint at an alliance with a crypto company, but its announcement signals deep interest in the digital asset world. Spot Crypto ETFs Bridges…
Share
BitcoinEthereumNews2025/12/05 18:24
Ripple Partners Trillion-Dollar Manager Franklin Templeton and DBS to Launch Tokenized Finance Solutions

Ripple Partners Trillion-Dollar Manager Franklin Templeton and DBS to Launch Tokenized Finance Solutions

Ripple, Franklin Templeton, and DBS have joined forces to advance tokenized finance through a new collaboration. The three firms signed a partnership to develop lending and trading tools using tokenized money market funds and Ripple’s new stablecoin, Ripple USD (RLUSD).Visit Website
Share
The Crypto Basic2025/09/18 17:21