Concentric Hack

Approximate loss $1.9M
Arbitrum
Compromised vault-upgrade authority

What happened

On January 22, 2024, a compromised Concentric administrator wallet enabled malicious vault upgrades. CertiK calculated approximately $1.85 million in losses, including tokens taken from users who had granted spending approvals.

Technical root cause

Compromised upgrade authority allowed malicious vault implementations to seize vault assets and approved user tokens.

How it happened

  1. The attacker used the compromised deployer wallet to transfer contract ownership.
  2. The new owner upgraded pool contracts with malicious code.
  3. Calls to adminMint() and burn() converted manipulated CONE-1 balances into vault assets.
  4. A second malicious contract took tokens covered by users' existing approvals.

Protocol details

Classification Infrastructure / Yield Aggregator / Social Engineering
Protocol Type Exploit/Access control
Affected asset / contract CONE
Implementation language Solidity
Protocol links Website @ConcentricFi

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.