The Ekubo crypto protocol became the target of a hacking attack. According to the latest data, losses on the Ethereum and Arbitrum networks amounted to approximately $1.4 million.
🔍 What happened?
The bad actors exploited a vulnerability in the EVM Router contracts version.
Mechanics: Hackers discovered a bug in the payCallback function, allowing them to drain funds from user wallets that had previously approved the protocol to use their tokens.
Scope: 85 transactions were executed. One of the major liquidity providers lost 17 WBTC due to unlimited approval.
✅ Who's safe?
Users on the Starknet network weren’t affected — the protocol architecture there is different, and funds remain safe. Also safe are those who didn’t interact with Ekubo on Ethereum and Arbitrum networks or didn’t grant permissions to vulnerable contracts.
🛡 Your actions right now:
If you've used Ekubo on ETH or Arbitrum networks, we strongly advise:
Use the Revoke.cash service.
Revoke allowances for Ekubo contracts (especially for addresses ending in ...60fd, ...edf2, and ...c47d).
Always set a Spending Limit instead of ‘infinite’ approval moving forward.
💡 Conclusion
This case once again proves: even a secure protocol can have vulnerable auxiliary tools. Regular wallet hygiene and checking approvals isn’t paranoia, but a necessity in the DeFi world.
💬 Community question: How often do you do a 'review' of your approvals, do you pay attention to limits when signing transactions? Share your protection methods in the comments! 👇
#Ekubo #DeFi #CryptoSecurity #ADPPayrollsSurge #Arbitrum #Starknet #Blockchain #SmartContract
