The USPD protocol just released an announcement confirming that it has suffered a meticulously planned attack.



The hacker employed a rather covert method—what's known as a "CPIMP attack" (Concealed Proxy in the Middle Proxy). Simply put, during the contract deployment phase, the attacker quietly managed to seize the admin privileges of the proxy contract in advance. To make matters worse, they disguised themselves as a legitimate, audited version and lay dormant for several months.

When the time was right, they launched the attack: minting approximately 98 million USPD tokens and then absconding with around 232 stETH.

The terrifying aspect of this attack method is that it can pass audit checks because everything appears normal on the surface. By the time it's discovered, the damage has already been done.
STETH-3.81%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
down_only_larryvip
· 18h ago
Damn, even the audit was fooled? This CPIMP attack is just insane. They waited for months before launching it—this guy really has nerves of steel.
View OriginalReply0
PretendingSeriousvip
· 18h ago
I was wondering how such a huge loophole could pass the audit. Turns out, the trap was set right from the deployment stage. This guy is ruthless.
View OriginalReply0
BtcDailyResearchervip
· 18h ago
Damn, this technique is insane. They lay low for months before making a move, and even audits can't detect it? That's just ridiculous.
View OriginalReply0
PhantomHuntervip
· 18h ago
Damn, they've been lurking for months before making a move. This technique is insane... Even audits couldn't catch it? I just want to know how the USPD team can even sleep at night.
View OriginalReply0
HashBanditvip
· 18h ago
yo this is exactly why i don't trust audits lmao... back in my mining days we at least had transparency with hashrate, now these protocols slip past auditors like it's nothing. 232 stETH gone just like that, brutal.
Reply0
CryptoDouble-O-Sevenvip
· 18h ago
Damn, even audits can't catch this? Then what can we trust?
View OriginalReply0
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)