• Politics
  • Business
  • Investing
  • Stock
No Result
View All Result
Retire Smart Strategies
  • Politics
  • Business
  • Investing
  • Stock
No Result
View All Result
Retire Smart Strategies
No Result
View All Result
Home Politics

DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

December 5, 2025
in Politics
DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

The post DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack appeared first on Coinpedia Fintech News

A decentralized finance platform called USPD has fallen victim to a complex security breach that resulted in approximately $1 million being stolen from its protocol. What first looked like a normal system setup months ago was actually a hidden trap waiting to strike. 

In the meantime, USPD is offering a 10% bounty if the attacker returns 90% of the stolen funds.

How the USPD Attack Happened?

According to blockchain security firm PeckShieldAlert, the attacker planted the trap all the way back on September 16, while the project was still being deployed. They used a clever technique during the proxy setup phase, gaining admin rights before USPD’s own deployment script could finish.

Meanwhile, this type of exploit is now being called a “CPIMP” attack, short for Clandestine Proxy In the Middle of Proxy.

#PeckShieldAlert @USPD_io has reported an exploit resulting in a loss of ~$1M. Please revoke all token approvals to USDP contract.https://t.co/4mQqoE8EWO pic.twitter.com/IRo50xqhJL

— PeckShieldAlert (@PeckShieldAlert) December 5, 2025

What made this attack particularly sneaky was how well it was hidden. The hacker installed what security experts describe as a “shadow” implementation that cleverly forwarded everything to USPD’s properly audited contract. 

By manipulating event data and storage information, they tricked blockchain explorer Etherscan into showing the legitimate, audited code, even though they had secretly planted their malicious version underneath.

Attack Finally Strikes, Losing $1 Million

After months of lying dormant and undetected, the attacker finally struck. They upgraded the proxy contract, minted around 98 million USPD tokens out of thin air, and withdrew approximately 232 stETH tokens before draining nearly $1 million in liquidity

The attacker operated through two addresses, now labeled “Infector” address (0x7C9…19d83 and the other was “Drainer” address (0x0883…3215A).

10% Bounty For The Attacker

The USPD team is working with law enforcement and white-hat researchers to track the stolen funds. They have asked all users to revoke approvals to stay safe.

They also said they are open to treating the hack as a “white-hat rescue” if the attacker comes forward. 

To encourage this, USPD is offering a 10% bounty if the attacker returns 90% of the stolen assets.

Previous Post

“Ethereum Price Could Surge Toward $62,000 in Long-Term Outlook.” Tom Lee Says

Next Post

Could This $0.035 New Crypto Repeat Early SHIB or DOGE Growth? Only 5% Supply Left

    Why subscribe?

    Subscribe to get full access to the newsletter and publication archives.

    Stay up-to-date
    Never miss an update - every new post is sent directly to your email inbox.

    Learn more >

    Categories

    • Business
    • Politics
    • Stock

    Recent News

    Pop Mart share price jumps after buyback, but H&S pattern points to a retreat

    Pop Mart share price jumps after buyback, but H&S pattern points to a retreat

    January 20, 2026
    Solana (SOL) Price Slips Below $130—Is $120 the Next Support to Watch?

    Solana (SOL) Price Slips Below $130—Is $120 the Next Support to Watch?

    January 20, 2026
    • About us
    • Contacts
    • Form page
    • Home

    Copyright © 2026 retiresmartstrategies.com | All Rights Reserved

    No Result
    View All Result
    • About us
    • Contacts
    • Form page
    • Home

    Copyright © 2026 retiresmartstrategies.com | All Rights Reserved