DeFi Protocol USPD Loses $1 Million in Sophisticated ’CPIMP’ Attack
Decentralized finance platform USPD has suffered a $1 million exploit through a meticulously planned attack dubbed 'CPIMP' (Clandestine Proxy In the Middle of Proxy). The breach traces back to September 16, when the attacker allegedly planted malicious code during the project's deployment phase.
Security firm PeckShieldAlert revealed the hacker gained admin rights during proxy setup, installing a hidden implementation that mirrored legitimate contract activity. The exploit remained undetected for months, with even blockchain explorers like Etherscan displaying audited code while funds were being siphoned.
USPD has offered a 10% bounty for the return of 90% of stolen assets. The incident highlights growing sophistication in DeFi attacks, with attackers now exploiting the time gap between project deployment and operational launch.