Aurellion Hack
What happened
On May 12, 2026, Aurellion Labs on Arbitrum was exploited for approximately $456,000 USDC after an attacker seized control of its diamond proxy.
A facet upgrade exposed initialize(address) but did not initialize its storage state. That left the initializer callable by an attacker, who could take ownership and use the diamond's upgrade path to install malicious logic.
How it happened
The attacker initialized the diamond, obtained ownership, added a malicious facet through diamondCut, and used that facet to pull USDC from wallets that had approved the proxy.
Protocol details
Evidence
- report @exvulsec incident report x.com
- report @Aurellion_Labs incident report x.com
- report @SlowMist_Team incident report x.com
- transaction Aurellion exploit transaction on Arbiscan arbiscan.io
- analysis DeFiLlama defillama.com
- analysis Verichains: Aurellion Labs Hack Analysis: Diamond Proxy Uninitialized Facet Exploit blog.verichains.io
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.