USPD Stablecoin Exploited via Sophisticated Proxy Attack, 232 stETH Drained
USPD.io's dollar-pegged stablecoin suffered a critical exploit on September 16, with attackers minting 98 million unauthorized tokens and siphoning 232 stETH. The breach targeted the protocol's proxy deployment process using a novel CPIMP (Clandestine Proxy In the Middle of Proxy) method, bypassing prior audits from security firms Nethermind and Resonance.
The attackers executed a 'Multicall3' transaction during deployment to gain administrative privileges prematurely. USPD.io has flagged malicious addresses and initiated a whitehat rescue operation while cooperating with authorities. The team maintains the Core smart contract remains sound, urging users to revoke approvals and avoid trading the compromised stablecoin.