• Мутки
• Темки
• Делюга
by @cryptophilos
Post #2308
1.09K
🚨Blockaid's exploit detection system has identified a USDC bridge possible exploit on Arbitrum
We detected an abnormal bridge withdrawal that extracted ~$24.15M USDC from an Arbitrum USDC custody bridge contract. The on-chain bridge logic was not bypassed; the malicious withdrawal was authorized by a quorum of hot-validator signatures and then finalized after the dispute period.
Exploit tx: https://arbiscan.io/tx/0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b
Withdrawal creation tx: https://arbiscan.io/tx/0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Loot wallet: https://arbiscan.io/address/0x2f2974fAbc54dbA33442261211c06BD20E0FEefc
Bridge contract: https://arbiscan.io/address/0xCb3B9A3E5668AFE84DC7A864B36b845dCE062e67
Finalizer: https://arbiscan.io/address/0x5553EA7Bda594aDE7AFe91D279779a42b2B84208
Withdrawal creation sender: https://arbiscan.io/address/0x32E3200D6E944cd9bD1C8C9865293B07206e7A01
Hot-validator signers used for the malicious withdrawal: https://arbiscan.io/address/0x00BB84aF06daC03BFe744Da13dF9D2D6fd8e77E5 https://arbiscan.io/address/0x27259f90D6ae500262AcE6E8428434e0c1f308F5 https://arbiscan.io/address/0x2e26dE22a92e41704B3eA00cc65a6CDA47b12c9e https://arbiscan.io/address/0x52D4D9AD78a53a69bD089eE8f282CE0Cd0506Da7 https://arbiscan.io/address/0xBB472BC3962Ad02Ac660429FdBB319B5BC66DA7b
Root cause: compromise or abuse of the bridge's hot-validator signing path. Five hot-validator signatures authorized a withdrawal of 24,150,000 USDC to the loot wallet, reaching 7,142 / 10,000 validator power (>2/3 quorum). The bridge contract then treated the withdrawal as valid and released funds after the 200-second dispute period.
The attacker subsequently bridged/laundered the proceeds to Ethereum: the same loot wallet received ~24.146M USDC minted on Ethereum in batches and forwarded the funds onward, consistent with movement of the stolen Arbitrum USDC.
We detected an abnormal bridge withdrawal that extracted ~$24.15M USDC from an Arbitrum USDC custody bridge contract. The on-chain bridge logic was not bypassed; the malicious withdrawal was authorized by a quorum of hot-validator signatures and then finalized after the dispute period.
Exploit tx: https://arbiscan.io/tx/0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b
Withdrawal creation tx: https://arbiscan.io/tx/0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 Loot wallet: https://arbiscan.io/address/0x2f2974fAbc54dbA33442261211c06BD20E0FEefc
Bridge contract: https://arbiscan.io/address/0xCb3B9A3E5668AFE84DC7A864B36b845dCE062e67
Finalizer: https://arbiscan.io/address/0x5553EA7Bda594aDE7AFe91D279779a42b2B84208
Withdrawal creation sender: https://arbiscan.io/address/0x32E3200D6E944cd9bD1C8C9865293B07206e7A01
Hot-validator signers used for the malicious withdrawal: https://arbiscan.io/address/0x00BB84aF06daC03BFe744Da13dF9D2D6fd8e77E5 https://arbiscan.io/address/0x27259f90D6ae500262AcE6E8428434e0c1f308F5 https://arbiscan.io/address/0x2e26dE22a92e41704B3eA00cc65a6CDA47b12c9e https://arbiscan.io/address/0x52D4D9AD78a53a69bD089eE8f282CE0Cd0506Da7 https://arbiscan.io/address/0xBB472BC3962Ad02Ac660429FdBB319B5BC66DA7b
Root cause: compromise or abuse of the bridge's hot-validator signing path. Five hot-validator signatures authorized a withdrawal of 24,150,000 USDC to the loot wallet, reaching 7,142 / 10,000 validator power (>2/3 quorum). The bridge contract then treated the withdrawal as valid and released funds after the 200-second dispute period.
The attacker subsequently bridged/laundered the proceeds to Ethereum: the same loot wallet received ~24.146M USDC minted on Ethereum in batches and forwarded the funds onward, consistent with movement of the stolen Arbitrum USDC.
- 🍾 2














