USPD Stablecoin Protocol Suffers 78-Day Proxy Exploit Despite Industry Patch
A critical vulnerability in USPD's deployment process allowed an attacker to maintain hidden control over the stablecoin protocol for nearly three months. The breach, stemming from a 24-second window during proxy initialization on September 16, enabled the minting of $1 million in unbacked tokens before being discovered in December.
Security analysts note the exploit Leveraged CPIMP - a vulnerability patched industry-wide in July. While audited code passed Nethermind and Resonance reviews, the malicious proxy injection went undetected as operations appeared normal throughout the 78-day compromise.
USPD now faces the dual challenge of launching a V2 iteration while establishing recovery pools for affected users. The incident underscores the persistent risks in smart contract deployment timing, even with audited code and known vulnerability patches in place.