Ekubo Protocol Hack
What happened
On 5 May 2026, a calldata-parsing flaw in Ekubo's immutable EVM HuffRouter contracts let an attacker spend ERC-20 approvals granted to those routers by other addresses. Ekubo's postmortem identified approximately $1.42 million taken from 31 addresses. The affected components were EVM routers on Ethereum and Arbitrum, not Ekubo Core, liquidity-provider positions, or Starknet.
Approval-bearing settlement logic read authorization-sensitive addresses from offsets relative to a decoded route, allowing attacker-supplied trailing calldata to replace the intended transferFrom payer. Such reads must be anchored to actual calldata boundaries and must never let untrusted bytes select a third-party payer.
How it happened
The router located settlement data from the logical end of a decoded route rather than the actual end of calldata. An attacker could append bytes that the route parser did not read, but which settlement later interpreted as router-created values. In the exploit, those bytes made an approved victim the transferFrom payer while the attacker received the withdrawal.
The first known Ethereum transaction repeated the route to drain 0.2 WBTC at a time. Because the deployed routers are immutable, Ekubo removed them from its interface, whitehatted finite approvals, and warned holders of remaining infinite approvals. A DAO contribution to a recovery fund is not treated here as confirmed victim recovery.
Protocol details
Security review history
- Code4rena View report
Evidence
Proof of concept
1 availableSources
- report Twitter/X Alert x.com
- report Twitter/X Alert x.com
- transaction First known Ekubo exploit transaction etherscan.io
- code Ekubo technical incident report github.com
- analysis DeFiLlama defillama.com
- analysis Ekubo Huff router approval incident blog.ekubo.org
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.