TLDR
US Permissionless Dollar (USPD) is the stablecoin that suffered a mint exploit, with unauthorized minting of approximately 98 million tokens and roughly $1 million in losses reported in early December (crypto news report).
- The attacker seized proxy admin during deployment and enabled unlimited minting of USPD (analysis).
- Estimated losses include about 232 stETH, valued near $1 million, with alerts to revoke approvals (market recap).
- A separate infinite-mint incident hit Yearns yETH pool (not a stablecoin) for about $9 million (incident summary).
Deep Dive
1. USPD Exploit Mechanics
USPDs breach was a deployment-time proxy takeover that allowed unauthorized minting. Reports describe a CPIMP-style attack leveraging Multicall3 to front-run initialization, seize proxy admin rights, and later mint about 98 million USPD (technical recap).
- The exploit installed shadow logic while forwarding calls to the legitimate contract, masking malicious behavior from users and explorers (technical recap).
- The team urged users to avoid buying the affected token and to revoke approvals, offering a whitehat recovery if most funds are returned (market recap).
Proxy and admin configurations are critical. Even audited logic can be undermined if deployment controls are compromised.
2. Impact Magnitude
Losses are estimated around $1 million, including about 232 stETH drained, with the unauthorized mint event persisting undetected for months before execution (market recap).
- The disclosure and user guidance were issued in early December with active coordination among security researchers and exchanges (technical recap).
The direct loss is modest in dollar terms, but mint exploits erode trust in a stablecoins supply integrity, which can impair liquidity and peg confidence.
3. Related Infinite-Mint Pattern (Not a Stablecoin)
Yearns yETH stableswap pool saw an infinite-mint bug in custom code, leading to roughly $9 million in losses and large yETH inflation before draining pool liquidity. Yearn stated core vaults were unaffected (incident summary).
- The attacker minted about 235 trillion yETH, swapped into ETH and LSTs, and moved about 1,000 ETH through Tornado Cash (incident summary).
Infinite-mint vulnerabilities remain a recurrent DeFi risk. Even when not a stablecoin, similar mint logic failures can cascade into pool drains that affect broader liquidity.
Conclusion
USPD is the stablecoin implicated in the latest mint exploit, with unauthorized supply creation and roughly $1 million in losses documented in early December. The separate Yearn yETH incident highlights a broader pattern of mint-related failures. The common thread is control at deployment and precision in token mint logic. Monitoring official advisories and revocation guidance is essential to protect stablecoin liquidity and peg confidence.
