Chi Protocol Hack

Reported loss $8K
Ethereum
Redeem Logic Flaw

What happened

On July 13, 2026, Chi Protocol's USC stablecoin system on Ethereum lost approximately $8,500 in a redemption-logic exploit. The attacker bought depegged USC cheaply and redeemed it against protocol collateral at the hardcoded $1 rate.

Technical root cause

ArbitrageV5.burn() used the hardcoded USC target price for redemption without enforcing the spot-price peg check used by mint(). This mint/burn asymmetry let below-peg USC be redeemed for full-value collateral.

How it happened

  1. The attacker acquired approximately 17,342 USC from a thin Uniswap V2 pool while USC traded below its peg, then called the ArbitrageV5 burn path to redeem collateral at the hardcoded $1 target.
  2. The transaction extracted approximately 4.66 WETH before the remaining assets were swapped back to ETH.

Protocol details

Classification Protocol Logic
Protocol Type Partially Algorithmic Stablecoin
Implementation language Solidity
Protocol links Website @ProtocolChi

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.