Fusion by IPOR Hack
What happened
On 6 January 2026, a legacy IPOR USDC Fusion Optimizer vault on Arbitrum was exploited for about $336,000 USDC. The incident combined a delegated admin account with an arbitrary-call-capable EIP-7702 delegate and missing validation of withdrawal fuse modules in the legacy vault.
Sensitive vault configuration relied on privileged delegated execution while the legacy withdrawal path did not strictly validate fuse modules. Arbitrary-call-capable delegated authority could therefore configure attacker-controlled logic.
Case & protocol details
Attack Timeline
Audit assessment
Review priorities based on the documented failure pattern in Fusion by IPOR (January 2026).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Access Control Attacks attack class for patterns
Evidence & learning
Sources and on-chain records
- report Report x.com
- report IPOR Fusion Optimizer postmortem blog.ipor.io
- transaction Transaction arbiscan.io
- analysis SlowMist Arbitrum incident record hacked.slowmist.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.