USPD Stablecoin Protocol Hacked: $1 Million Lost in Sophisticated Attack
USPD stablecoin protocol lost about $1 million after attackers exploited a proxy deployment vulnerability, minting 98 million tokens and draining liquidity. The team urges users to revoke approvals and is seeking to recover the stolen funds.
The USPD decentralized stablecoin protocol has suffered a sophisticated security breach, resulting in the loss of approximately $1 million. Attackers exploited a vulnerability during the proxy contract's deployment, gaining administrative control through a method known as the "CPIMP" (Clandestine Proxy In the Middle of Proxy) attack. This allowed them to mint about 98 million unauthorized USPD tokens and withdraw around 232 stETH, draining the protocol's liquidity. The exploit involved installing a shadow contract that forwarded calls to the legitimate, audited code, deceiving users and block explorers. The breach was not due to flaws in the audited smart contract logic but rather the compromise of administrative privileges during deployment. USPD has urged users to revoke approvals and avoid buying the token, while working with law enforcement and security researchers to trace and recover the stolen funds. The team has offered the attacker a 10% bug bounty if the assets are returned. This incident highlights ongoing security challenges in the DeFi sector, particularly regarding governance and administrative controls.