Fusion (by IPOR) team urgently issues a security notice. After receiving a system alert on January 6th, it was discovered that the Fusion optimizer Vault on the Arbitrum network was exploited by hackers. Through technical investigation, the attackers successfully executed malicious transactions by exploiting a configuration vulnerability in the contract, resulting in a direct loss of 336,000 USDC.



According to preliminary analysis, this attack was highly targeted — only specific versions of the old Fusion Vault were affected. Due to the unique parameter configuration of this Vault, it became the sole entry point for the attack. This means that other versions of the Vault were not impacted, and user assets remain relatively safe.

Although the loss of 336,000 USDC seems significant, considering the overall scale of the Fusion ecosystem, the impact of this incident is manageable. The IPOR team has activated an emergency response mechanism, is strengthening smart contract audits, and plans to release an upgrade solution. Users are also advised to follow official notifications for timely updates on security patches.
USDC0.04%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
LayerZeroHerovip
· 01-07 03:17
Another configuration vulnerability. DeFi is really exciting these days, haha.
View OriginalReply0
AirdropDreamervip
· 01-07 03:13
Another configuration vulnerability. Why does this thing keep appearing? --- 33.6K is gone, and they say the impact is controllable. So how much loss is considered a big deal? --- Fortunately, I didn't use that old version, but I still feel uneasy. --- Urgent announcement: upgrade when needed, don't wait for the next problem to occur. --- Only specific versions are affected? How can that be proven? How do I know if I am using that version? --- Arbitrum has another issue. This chain really can't hold up anymore. --- They say the impact is controllable, so I feel reassured. Anyway, the loss isn't in my wallet. --- The configuration vulnerability sounds nice, but honestly, it's just poor code review, right? --- Hurry up and release a patch, or who will dare to use it?
View OriginalReply0
ForkInTheRoadvip
· 01-07 03:04
It's another configuration vulnerability causing issues; this time, only the old version was affected. Here comes another wave, and every time they say "impact is controllable"... Really? 336,000 gone, can't settle this account. By the way, why is it always hacked? What are audits even doing? If you ask me, the V1 version's flaw has finally been exposed. Let's wait for the patch; who still trusts any security promises now? The old contract's configuration was so poorly set up—how did it pass the audit before?
View OriginalReply0
ApeDegenvip
· 01-07 03:00
Another configuration vulnerability, how many times has this happened now?
View OriginalReply0
NotFinancialAdvicevip
· 01-07 02:51
It's another configuration vulnerability. These teams really need to review their code thoroughly.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • بالعربية
  • Português (Brasil)
  • 简体中文
  • English
  • Español
  • Français (Afrique)
  • Bahasa Indonesia
  • 日本語
  • Português (Portugal)
  • Русский
  • 繁體中文
  • Українська
  • Tiếng Việt