Fusion by IPOR Hack

TOTAL LOST $336K
Low EIP-7702 Delegation / Arbitrary External Call / Malicious Module Configuration arbitrum
Chain arbitrum Primary network
Recovered - No recovery reported
Loss Rank #1328 All-time
Protocol Type Yield Aggregator Target category

What happened

On 6 January 2026, a legacy IPOR USDC Fusion Optimizer vault on Arbitrum was exploited for about $336,000 USDC. The incident combined a delegated admin account with an arbitrary-call-capable EIP-7702 delegate and missing validation of withdrawal fuse modules in the legacy vault.

Technical Root Cause

Sensitive vault configuration relied on privileged delegated execution while the legacy withdrawal path did not strictly validate fuse modules. Arbitrary-call-capable delegated authority could therefore configure attacker-controlled logic.

Case & protocol details

Classification Protocol Logic / Access Control
Protocol Type Yield Aggregator
Smart Contract Language Solidity
Official Website app.ipor.io/fusion
Protocol Twitter/X @ipor_io

Attack Timeline

A privileged administrator EOA had delegated execution to a contract exposing arbitrary external calls. The attacker used that authority to configure a malicious fuse in the legacy vault and invoked the withdrawal flow. Because the vault did not strictly validate the configured fuse, it executed attacker-controlled logic and transferred assets out. IPOR's postmortem states the necessary conditions were unique to this legacy vault; the incident should not be represented as an EIP-7702 protocol flaw or a compromise of all Fusion vaults.

Audit assessment

Review priorities based on the documented failure pattern in Fusion by IPOR (January 2026).

Critical checks

  • Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Access Control Attacks attack class for patterns

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.