TLDR
The stablecoin protocol exploited today is US Permissionless Dollar (USPD), with about $1 million drained via unauthorized minting and proxy control according to the incident report.
- Attackers minted roughly 98 million USPD and removed ~232 stETH (~$1 million) per the disclosure.
- Root cause cited as a CPIMP proxy?layer attack during deployment, not core logic flaws, per the report above.
- The team urged users not to buy USPD and to revoke approvals until further notice per the notice.
Deep Dive
1. What Happened
USPD disclosed that an attacker gained hidden proxy admin control months ago and used it to mint new tokens and drain funds.
- The breach led to unauthorized minting of approximately 98 million USPD and removal of roughly 232 stETH (~$1 million) from reserves per the USPD disclosure.
- A separate market recap also flagged a ~$1 million exploit and warned users to revoke approvals, aligning with the above details in the morning report.
The exploit is material for a smaller stablecoin protocol, and immediate user actions (like approval revocations) help reduce follow?on risk.
2. Why It Happened
USPD attributes the breach to a sophisticated proxy?contract attack during deployment, not its audited smart contract logic.
- The team described a CPIMP attack where the attacker front?ran proxy initialization, seized admin rights, and implanted shadow implementation, allowing later mintingper the technical explanation.
- USPD says firms such as Nethermind and Resonance had reviewed core logic, consistent with their claim that the vulnerability was in proxy control rather than audited logic per the report above.
Proxy patterns introduce a deployment?phase attack surface. Even audited logic can be undermined if proxy admin controls are compromised.
3. Immediate Steps
USPD warned not to buy USPD and to revoke approvals, while pursuing recovery avenues.
- Guidance: avoid purchasing USPD and revoke approvals; team is collaborating with researchers and exchanges and offered a whitehat recovery path per the incident notice.
- Context: This follows other recent DeFi exploits (for example Yearns yETH StableSwap incident for ~$9 million) per a news report.
If you interacted with USPD, mitigate exposure by removing permissions and waiting for verified recovery updates; broader DeFi risk awareness is warranted given recent exploit cadence.
Conclusion
USPD suffered a targeted proxy?contract exploit enabling unauthorized minting and roughly $1 million in losses, with the team advising users to revoke approvals and avoid the token for now per their notice. The mechanics point to deployment?phase proxy risks rather than audited logic, underscoring that stablecoin protocols must harden admin and initialization paths to protect reserves.
