The post USPD stablecoin protocol exploited for $1M via proxy breach appeared on BitcoinEthereumNews.com. USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. Summary USPD suffered an exploit after an attacker seized proxy admin rights during deployment. The breach led to unauthorized USPD minting and stETH outflows worth about $1 million. The incident adds to a month of major exploits affecting exchanges and decentralized finance protocols. USPD disclosed the incident on Dec. 5, saying the exploit allowed an attacker to mint roughly 98 million USPD and remove about 232 stETH, worth around $1 million. The team urged users not to buy the token and to revoke approvals until further notice. Attackers used hidden proxy control  The protocol stressed that its audited smart contract logic was not the source of the failure. USPD said firms such as Nethermind and Resonance had reviewed the code, and internal tests confirmed expected behavior. Instead, the breach came from what the team described as a “CPIMP” attack, which is a tactic that targets the deployment window of a proxy contract. 🚨 URGENT SECURITY ALERT: USPD PROTOCOL EXPLOIT 🚨 1/ We have confirmed a critical exploit of the USPD protocol resulting in unauthorized minting and liquidity draining. Please DO NOT buy USPD. Revoke all approvals immediately. — USPD.IO | The Dollar of the Decentralized Nation (@USPD_io) December 4, 2025 According to USPD, the attacker front-ran the initialization process on Sept. 16 using a Multicall3 transaction. The attacker jumped in before the deployment script finished, grabbed admin access, and slipped in a hidden proxy implementation. In order to keep the malicious setup hidden from users, auditors, and even Etherscan, that shadow version forwarded calls to the audited contract. The camouflage worked because the attacker manipulated event data and spoofed storage… The post USPD stablecoin protocol exploited for $1M via proxy breach appeared on BitcoinEthereumNews.com. USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds. Summary USPD suffered an exploit after an attacker seized proxy admin rights during deployment. The breach led to unauthorized USPD minting and stETH outflows worth about $1 million. The incident adds to a month of major exploits affecting exchanges and decentralized finance protocols. USPD disclosed the incident on Dec. 5, saying the exploit allowed an attacker to mint roughly 98 million USPD and remove about 232 stETH, worth around $1 million. The team urged users not to buy the token and to revoke approvals until further notice. Attackers used hidden proxy control  The protocol stressed that its audited smart contract logic was not the source of the failure. USPD said firms such as Nethermind and Resonance had reviewed the code, and internal tests confirmed expected behavior. Instead, the breach came from what the team described as a “CPIMP” attack, which is a tactic that targets the deployment window of a proxy contract. 🚨 URGENT SECURITY ALERT: USPD PROTOCOL EXPLOIT 🚨 1/ We have confirmed a critical exploit of the USPD protocol resulting in unauthorized minting and liquidity draining. Please DO NOT buy USPD. Revoke all approvals immediately. — USPD.IO | The Dollar of the Decentralized Nation (@USPD_io) December 4, 2025 According to USPD, the attacker front-ran the initialization process on Sept. 16 using a Multicall3 transaction. The attacker jumped in before the deployment script finished, grabbed admin access, and slipped in a hidden proxy implementation. In order to keep the malicious setup hidden from users, auditors, and even Etherscan, that shadow version forwarded calls to the audited contract. The camouflage worked because the attacker manipulated event data and spoofed storage…

USPD stablecoin protocol exploited for $1M via proxy breach

2025/12/05 15:18

USPD is facing a severe security breach after an attacker quietly gained control of its proxy contract months ago and used that access to mint new tokens and drain funds.

Summary

  • USPD suffered an exploit after an attacker seized proxy admin rights during deployment.
  • The breach led to unauthorized USPD minting and stETH outflows worth about $1 million.
  • The incident adds to a month of major exploits affecting exchanges and decentralized finance protocols.

USPD disclosed the incident on Dec. 5, saying the exploit allowed an attacker to mint roughly 98 million USPD and remove about 232 stETH, worth around $1 million. The team urged users not to buy the token and to revoke approvals until further notice.

Attackers used hidden proxy control 

The protocol stressed that its audited smart contract logic was not the source of the failure. USPD said firms such as Nethermind and Resonance had reviewed the code, and internal tests confirmed expected behavior. Instead, the breach came from what the team described as a “CPIMP” attack, which is a tactic that targets the deployment window of a proxy contract.

According to USPD, the attacker front-ran the initialization process on Sept. 16 using a Multicall3 transaction. The attacker jumped in before the deployment script finished, grabbed admin access, and slipped in a hidden proxy implementation.

In order to keep the malicious setup hidden from users, auditors, and even Etherscan, that shadow version forwarded calls to the audited contract.

The camouflage worked because the attacker manipulated event data and spoofed storage slots so that block explorers displayed the legitimate implementation. This left the attacker in full control for months until they upgraded the proxy and executed the minting event that drained the protocol.

USPD said it is working with law enforcement, security researchers, and major exchanges to trace funds and halt further movement. The team has offered the attacker a chance to return 90% of the assets under a standard bug-bounty structure, saying it would treat the action as a whitehat recovery if the funds are sent back.

Exploit adds to a month of heavy

The USPD incident arrives during one of the another active periods for exploits this year, with losses across December already passing $100 million.

Upbit, one of South Korea’s largest exchanges, confirmed a $30 million breach tied to Lazarus Group earlier this week. Investigators say the attackers posed as internal administrators to obtain access, continuing a pattern that has pushed Lazarus-linked thefts above $1 billion this year.

Yearn Finance also faced an early-December exploit affecting its legacy yETH token contract. Attackers used a bug that allowed unlimited minting, producing trillions of tokens in one transaction and draining about $9 million in value.

The run of incidents highlights the rising sophistication in DeFi-focused attacks, particularly those that target proxy contracts, admin keys, and legacy systems. Security teams say interest is picking up around decentralized multi-party computation tools and hardened deployment frameworks as protocols look to reduce the impact of single-point failures.

Source: https://crypto.news/uspd-stablecoin-protocol-exploited-proxy-breach-2025/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pepeto vs Blockdag Vs Layer Brett Vs Remittix and Little Pepe

Pepeto vs Blockdag Vs Layer Brett Vs Remittix and Little Pepe

The post Pepeto vs Blockdag Vs Layer Brett Vs Remittix and Little Pepe appeared on BitcoinEthereumNews.com. Crypto News 18 September 2025 | 05:39 Hunting the best crypto investment in 2025? Presales can flip a portfolio fast and sometimes change a life overnight when you choose well, which is why we start with receipts instead of slogans and cut straight to what’s live, audited, and usable today, not vague aspirations likely to drift as cycles turn and narratives fade for months. In this head-to-head we put Pepeto (PEPETO) up against Blockdag, Layer Brett, Remittix, and Little Pepe using simple yardsticks, team intent and delivery, on-chain proofs, tokenomics clarity, DEX and bridge readiness, PayFi rails, staking, and listing prep, so you can act on facts, not hype, and decide confidently before the next leg higher catches you watching from the sidelines. Pepeto’s Utility Play: Zero-Fee DEX, Bridge, And StrongPotential Pepeto treats the meme coin playbook like a platform brief, not a joke. The team ships fast, polishes details, and shows up weekly, aiming for staying power rather than a momentary pop. A hard-capped design anchors PepetoSwap, a zero-fee exchange where every trade routes through PEPETO for built-in usage instead of buzz. Already 850+ projects have applied to list, fertile ground for volume if listings follow. A built-in cross-chain bridge adds smart routing to unify liquidity, cut extra hops, and reduce slippage, turning activity into steady token demand because every swap touches PEPETO. Pepeto is audited by independent experts Solidproof and Coinsult, a trust marker reflected in more than $6,7 Million already raised in presale. Early momentum is visible. The presale puts early buyers at the front of the line with staking and stage-based price increases, and that line is getting long. Utility plus purpose, culture plus tools, the combo that tends to run farther than hype alone. Translation for you: Pepeto is graduating from noise to usage. If…
Share
BitcoinEthereumNews2025/09/18 10:41
Western Union Eyes Stablecoin Card for Inflation Zones

Western Union Eyes Stablecoin Card for Inflation Zones

The post Western Union Eyes Stablecoin Card for Inflation Zones appeared on BitcoinEthereumNews.com. Western Union is building a stablecoin-backed prepaid card targeting countries with high inflation rates. Summary Western Union is creating a stablecoin-backed prepaid card for inflation-heavy economies. The USDPT token on Solana launches in 2026, integrating with the firm’s remittance network. Partnership with Rain enables Visa stablecoin cards and crypto-to-cash conversions. The money transfer giant plans to offer the product in markets where local currency depreciation erodes purchasing power, CFO Matthew Cagwin told the UBS Global Technology and AI conference. Cagwin pointed to Argentina as a prime use case, where inflation exceeded 200% last year. The dollar-denominated card would help preserve value for remittance recipients in economies facing rapid currency devaluation. Rain partnership brings Visa stablecoin cards Western Union has partnered with Rain to issue Visa cards linked to stablecoins. The collaboration allows users to convert digital assets stored in wallets connected to Rain’s platform into local cash at Western Union branches. The company is building on-ramps and off-ramps within its digital asset network to reduce banking system dependence and accelerate fund settlement. “We’re working with several providers to build this infrastructure,” Cagwin stated. Western Union plans to launch the US Dollar Payment Token (USDPT) in 2026, a stablecoin issued by Anchorage Digital on the Solana network. The token will integrate with the company’s broader digital asset strategy. The prepaid card will function as a bridge between stablecoins and everyday spending in high-inflation economies. Users receive remittances loaded onto cards denominated in dollars. The cards can be spent at merchants or withdrawn as cash at Western Union locations. Company reverses decade-long crypto skepticism Western Union maintained a dismissive stance toward cryptocurrencies for years. In 2017, Chief Technology Officer David Thompson questioned Bitcoin’s viability as currency, comparing crypto to commodities rather than functional money. The company argued that digital assets lacked governance,…
Share
BitcoinEthereumNews2025/12/07 02:47