Aurellion Hack

Reported loss $456K
Arbitrum
Access Control

What happened

On May 12, 2026, Aurellion Labs on Arbitrum was exploited for approximately $456,000 USDC after an attacker seized control of its diamond proxy.

Technical root cause

A facet upgrade exposed initialize(address) but did not initialize its storage state. That left the initializer callable by an attacker, who could take ownership and use the diamond's upgrade path to install malicious logic.

How it happened

The attacker initialized the diamond, obtained ownership, added a malicious facet through diamondCut, and used that facet to pull USDC from wallets that had approved the proxy.

Protocol details

Classification Other / Access Control
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol links Website @Aurellion_Labs

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.