USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. USPD disclosed the incident on Dec. 5, saying the exploit…USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. USPD disclosed the incident on Dec. 5, saying the exploit…

Decentralized stablecoin protocol USPD hit by $1M exploit

2025/12/05 15:14

USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds.

Summary
  • USPD suffered an exploit after an attacker seized proxy admin rights during deployment.
  • The breach led to unauthorized USPD minting and stETH outflows worth about $1 million.
  • The incident adds to a month of major exploits affecting exchanges and decentralized finance protocols.

USPD disclosed the incident on Dec. 5, saying the exploit allowed an attacker to mint roughly 98 million USPD and remove about 232 stETH, worth around $1 million. The team urged users not to buy the token and to revoke approvals until further notice.

Attackers used hidden proxy control 

The protocol stressed that its audited smart contract logic was not the source of the failure. USPD said firms such as Nethermind and Resonance had reviewed the code, and internal tests confirmed expected behavior. Instead, the breach came from what the team described as a “CPIMP” attack, which is a tactic that targets the deployment window of a proxy contract.

According to USPD, the attacker front-ran the initialization process on Sept. 16 using a Multicall3 transaction. The attacker jumped in before the deployment script finished, grabbed admin access, and slipped in a hidden proxy implementation.

In order to keep the malicious setup hidden from users, auditors, and even Etherscan, that shadow version forwarded calls to the audited contract.

The camouflage worked because the attacker manipulated event data and spoofed storage slots so that block explorers displayed the legitimate implementation. This left the attacker in full control for months until they upgraded the proxy and executed the minting event that drained the protocol.

USPD said it is working with law enforcement, security researchers, and major exchanges to trace funds and halt further movement. The team has offered the attacker a chance to return 90% of the assets under a standard bug-bounty structure, saying it would treat the action as a whitehat recovery if the funds are sent back.

Exploit adds to a month of heavy

The USPD incident arrives during one of the another active periods for exploits this year, with losses across December already passing $100 million.

Upbit, one of South Korea’s largest exchanges, confirmed a $30 million breach tied to Lazarus Group earlier this week. Investigators say the attackers posed as internal administrators to obtain access, continuing a pattern that has pushed Lazarus-linked thefts above $1 billion this year.

Yearn Finance also faced an early-December exploit affecting its legacy yETH token contract. Attackers used a bug that allowed unlimited minting, producing trillions of tokens in one transaction and draining about $9 million in value.

The run of incidents highlights the rising sophistication in DeFi-focused attacks, particularly those that target proxy contracts, admin keys, and legacy systems. Security teams say interest is picking up around decentralized multi-party computation tools and hardened deployment frameworks as protocols look to reduce the impact of single-point failures.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Dogecoin, HBAR Rank High On Watchlists But One Crypto Is Stealing The Show

Dogecoin, HBAR Rank High On Watchlists But One Crypto Is Stealing The Show

The post Dogecoin, HBAR Rank High On Watchlists But One Crypto Is Stealing The Show appeared on BitcoinEthereumNews.com. Crypto traders searching for the best crypto to buy now are keeping a close eye on Dogecoin (DOGE) and Hedera (HBAR), two altcoins that remain top picks for September. DOGE continues to benefit from its loyal community and brand recognition, while HBAR’s enterprise partnerships keep it relevant as a layer-1 solution. But despite these strong contenders, analysts say one project is stealing the show — Layer Brett ($LBRETT), a fast-growing Ethereum Layer 2 that has taken the market by storm. Why Dogecoin and HBAR are still relevant Dogecoin remains a fan favorite, with its meme status and history of viral rallies making it a top speculative asset. Analysts believe DOGE could see another strong run in the next bull market, especially if Elon Musk tweets about it or if a DOGE payment integration is announced. In 2021, DOGE’s price rallied thousands of percent, proving that viral moments can still drive massive upside when the community is fully engaged. HBAR, meanwhile, is considered one of the most technically advanced layer 1 blockchains, its hashgraph consensus and enterprise partnerships gave it a unique edge. Projects in sectors like supply chain, tokenized assets, and enterprise data security continue to choose HBAR, which helps support steady price appreciation. Price predictions for HBAR suggest consistent growth into 2026 as adoption expands. Layer Brett: The real market disruptor While DOGE and HBAR are strong players, Layer Brett is where traders are seeing the most explosive potential. Built on Ethereum Layer 2, $LBRETT offers lightning-fast transactions, near-zero fees, and security backed by Ethereum. Its rapidly growing social presence, with thousands of new community members joining weekly, is driving massive buzz. Analysts say this mix of speed, low cost, and meme energy is creating a narrative that could dominate the next bull run. Key reasons analysts are calling…
Share
BitcoinEthereumNews2025/09/21 06:34
Will Bitcoin Beat S&P 500 Index? ‘Forever,’ Says Michael Saylor

Will Bitcoin Beat S&P 500 Index? ‘Forever,’ Says Michael Saylor

The post Will Bitcoin Beat S&P 500 Index? ‘Forever,’ Says Michael Saylor appeared on BitcoinEthereumNews.com. In recent Bitcoin news, Strategy CEO Michael Saylor once again made a bold claim about the future of Bitcoin (BTC USD). He said that Bitcoin will outperform the S&P 500 “forever.” According to him, the index would lose nearly 29% in value each year when compared to the top cryptocurrency. In his statement, Saylor highlighted Bitcoin’s strength as a long-term investment. He believes its fixed supply and global adoption will continue to drive its value higher. On the other hand, he argued that a traditional index like the S&P 500 will struggle to keep pace. Bitcoin News: Why is it “Digital Capital,” Stronger Than S&P 500 In his interview with Coin Stories, MicroStrategy executive chairman, Michael Saylor, explained Bitcoin was a unique digital investment vehicle. According to him, it grows in value much faster than traditional assets. Saylor noted that the S&P 500’s average return is often treated as the standard measure of investment growth. However, he emphasized that Bitcoin (BTC USD) consistently outpaces this benchmark. This difference, he said, highlights a clear performance gap. Because of this, Saylor believes a major financial shift is taking place. He argued that Bitcoin is emerging as a superior choice for investors, an increasingly popular opinion as witnessed in recent news. In his view, it also serves as stronger collateral compared to traditional assets. In his view, Bitcoin’s steady appreciation gives investors a chance to create new forms of credit backed by the asset. He explained that Bitcoin-backed loans could last longer, deliver higher returns, and reshape global finance. Michael Saylor also highlighted that this perspective influenced his role in policy discussions. Recently, he joined other crypto executives in a meeting to advocate for the strategic Bitcoin reserve bill. In addition, he compared Bitcoin’s reliability with weakness in traditional currencies. He argued that…
Share
BitcoinEthereumNews2025/09/20 18:34