BTCC / BTCC Square / Global Cryptocurrency /
USPD Stablecoin Protocol Suffers 78-Day Proxy Exploit Despite Industry Patch

USPD Stablecoin Protocol Suffers 78-Day Proxy Exploit Despite Industry Patch

Published:
2025-12-10 18:18:03
9
2
BTCCSquare news:

A critical vulnerability in USPD's deployment process allowed an attacker to maintain hidden control over the stablecoin protocol for nearly three months. The breach, stemming from a 24-second window during proxy initialization on September 16, enabled the minting of $1 million in unbacked tokens before being discovered in December.

Security analysts note the exploit Leveraged CPIMP - a vulnerability patched industry-wide in July. While audited code passed Nethermind and Resonance reviews, the malicious proxy injection went undetected as operations appeared normal throughout the 78-day compromise.

USPD now faces the dual challenge of launching a V2 iteration while establishing recovery pools for affected users. The incident underscores the persistent risks in smart contract deployment timing, even with audited code and known vulnerability patches in place.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users

All articles reposted on this platform are sourced from public networks and are intended solely for the purpose of disseminating industry information. They do not represent any official stance of BTCC. All intellectual property rights belong to their original authors. If you believe any content infringes upon your rights or is suspected of copyright violation, please contact us at [email protected]. We will address the matter promptly and in accordance with applicable laws.BTCC makes no explicit or implied warranties regarding the accuracy, timeliness, or completeness of the republished information and assumes no direct or indirect liability for any consequences arising from reliance on such content. All materials are provided for industry research reference only and shall not be construed as investment, legal, or business advice. BTCC bears no legal responsibility for any actions taken based on the content provided herein.