Stablecoin protocol USPD suffers "CPIMP" attack, with losses of approximately $1 million

PANews, December 5 — According to PeckShieldAlert, the stablecoin project USPD has suffered a major security breach, resulting in a loss of approximately $1 million. USPD has officially confirmed that the protocol was exploited, with the attacker minting tokens without authorization and draining liquidity. The team has issued an urgent warning for users to immediately revoke all token approvals to the USPD contract.

The USPD protocol has confirmed it was hit by a “CPIMP” attack. During deployment, the attacker used Multicall3 to preemptively initialize the proxy, seize admin privileges, and masquerade as an audited implementation contract. The team states this was not a contract logic vulnerability; instead, after being concealed for several months, the attacker upgraded the proxy, minted about 98M USPD, and transferred approximately 232 stETH. USPD has asked users to immediately revoke all approvals and has published the attacker addresses: 0x7C97…9d83 (Infector), 0x0833…215A (Drainer). They are cooperating with law enforcement and white hats to track the attacker and have promised a 10% bounty for any recoverable funds.

STETH-0.6%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)