Bitcoin Move Now
  • Editor’s pick
  • Business
  • Investing
  • Stock
No Result
View All Result
  • Editor’s pick
  • Business
  • Investing
  • Stock
No Result
View All Result
Bitcoin Move Now
No Result
View All Result
Home Editor's pick

DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

December 5, 2025
in Editor's pick
DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack

The post DeFi Protocol USPD Loses $1 Million in “CPIMP” Attack appeared first on Coinpedia Fintech News

A decentralized finance platform called USPD has fallen victim to a complex security breach that resulted in approximately $1 million being stolen from its protocol. What first looked like a normal system setup months ago was actually a hidden trap waiting to strike. 

In the meantime, USPD is offering a 10% bounty if the attacker returns 90% of the stolen funds.

How the USPD Attack Happened?

According to blockchain security firm PeckShieldAlert, the attacker planted the trap all the way back on September 16, while the project was still being deployed. They used a clever technique during the proxy setup phase, gaining admin rights before USPD’s own deployment script could finish.

Meanwhile, this type of exploit is now being called a “CPIMP” attack, short for Clandestine Proxy In the Middle of Proxy.

#PeckShieldAlert @USPD_io has reported an exploit resulting in a loss of ~$1M. Please revoke all token approvals to USDP contract.https://t.co/4mQqoE8EWO pic.twitter.com/IRo50xqhJL

— PeckShieldAlert (@PeckShieldAlert) December 5, 2025

What made this attack particularly sneaky was how well it was hidden. The hacker installed what security experts describe as a “shadow” implementation that cleverly forwarded everything to USPD’s properly audited contract. 

By manipulating event data and storage information, they tricked blockchain explorer Etherscan into showing the legitimate, audited code, even though they had secretly planted their malicious version underneath.

Attack Finally Strikes, Losing $1 Million

After months of lying dormant and undetected, the attacker finally struck. They upgraded the proxy contract, minted around 98 million USPD tokens out of thin air, and withdrew approximately 232 stETH tokens before draining nearly $1 million in liquidity

The attacker operated through two addresses, now labeled “Infector” address (0x7C9…19d83 and the other was “Drainer” address (0x0883…3215A).

10% Bounty For The Attacker

The USPD team is working with law enforcement and white-hat researchers to track the stolen funds. They have asked all users to revoke approvals to stay safe.

They also said they are open to treating the hack as a “white-hat rescue” if the attacker comes forward. 

To encourage this, USPD is offering a 10% bounty if the attacker returns 90% of the stolen assets.

Previous Post

“Ethereum Price Could Surge Toward $62,000 in Long-Term Outlook.” Tom Lee Says

Next Post

Could This $0.035 New Crypto Repeat Early SHIB or DOGE Growth? Only 5% Supply Left

    Join our mailing list to get access to special deals, promotions, and insider information. Your exclusive benefits await! Enjoy personalized recommendations, first dibs on sales, and members-only content that makes you feel like a true VIP. Sign up now and start saving!


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Disclaimer: bitcoinmovenow.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Recent News

    US Government Shutdown in January Risk Hits 38% Amid Budget Deadlock

    US Government Shutdown in January Risk Hits 38% Amid Budget Deadlock

    December 27, 2025
    Crypto Analyst Calls XRP a “Zombie Asset” Despite Ripple’s Growth

    Crypto Analyst Calls XRP a “Zombie Asset” Despite Ripple’s Growth

    December 27, 2025
    • About us
    • Contacts
    • Privacy Policy
    • Terms and Conditions
    • Email Whitelisting

    Copyright © 2025 bitcoinmovenow.com | All Rights Reserved

    No Result
    View All Result
    • About us
    • Contacts
    • Email Whitelisting
    • Home 1
    • Privacy Policy
    • Terms and Conditions
    • Thank you

    Copyright © 2025 bitcoinmovenow.com | All Rights Reserved