Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

Coinpedia2025/12/05 18:09
By:Coinpedia
Story Highlights

A decentralized finance platform called USPD has fallen victim to a complex security breach that resulted in approximately $1 million being stolen from its protocol. What first looked like a normal system setup months ago was actually a hidden trap waiting to strike. 

Advertisement

In the meantime, USPD is offering a 10% bounty if the attacker returns 90% of the stolen funds.

According to blockchain security firm PeckShieldAlert, the attacker planted the trap all the way back on September 16, while the project was still being deployed. They used a clever technique during the proxy setup phase, gaining admin rights before USPD’s own deployment script could finish.


Meanwhile, this type of exploit is now being called a “CPIMP” attack, short for Clandestine Proxy In the Middle of Proxy.

#PeckShieldAlert @USPD_io has reported an exploit resulting in a loss of ~$1M. Please revoke all token approvals to USDP contract. https://t.co/4mQqoE8EWO pic.twitter.com/IRo50xqhJL

— PeckShieldAlert (@PeckShieldAlert) December 5, 2025

What made this attack particularly sneaky was how well it was hidden. The hacker installed what security experts describe as a “shadow” implementation that cleverly forwarded everything to USPD’s properly audited contract. 

By manipulating event data and storage information, they tricked blockchain explorer Etherscan into showing the legitimate, audited code, even though they had secretly planted their malicious version underneath.

  • Also Read :
  •   Upbit Hit by $36M Solana Hack, Vows Full Reimbursement After Major Breach
  •   ,

After months of lying dormant and undetected, the attacker finally struck. They upgraded the proxy contract, minted around 98 million USPD tokens out of thin air, and withdrew approximately 232 stETH tokens before draining nearly $1 million in liquidity

The attacker operated through two addresses, now labeled “Infector” address (0x7C9…19d83 and the other was “Drainer” address (0x0883…3215A).

The USPD team is working with law enforcement and white-hat researchers to track the stolen funds. They have asked all users to revoke approvals to stay safe.

They also said they are open to treating the hack as a “white-hat rescue” if the attacker comes forward. 

To encourage this, USPD is offering a 10% bounty if the attacker returns 90% of the stolen assets.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bloomberg: Power Theft Exceeds $1 Billion as Malaysia Bitcoin Mining Rigs Overwhelm

Malaysia has uncovered approximately 14,000 illegal cryptocurrency mining sites in the past five years, causing the state-owned power company losses of over $1.1 billion. In response, the local government established a special committee in November 2025 to consider a total ban on mining,

BlockBeats2025/12/06 11:00
Bloomberg: Power Theft Exceeds $1 Billion as Malaysia Bitcoin Mining Rigs Overwhelm
© 2025 Bitget