Gyroscope Hack
What happened
On 30 January 2026, an attacker exploited Gyroscope's Arbitrum-to-Ethereum GYD bridge. The attacker bridged one wei of GYD to the Ethereum GYD token contract with malicious calldata, creating an unlimited approval that was used to withdraw more than 6 million GYD. CertiK reported that the available liquidity extracted was approximately $807,000.
The bridge allowed arbitrary calldata to execute against a user-chosen recipient, including the GYD token contract. Untrusted cross-chain message data must not be able to create ERC-20 allowances or invoke arbitrary selectors on security-critical recipients.
Case & protocol details
Attack Timeline
Gyroscope's bridge accepted a user-supplied destination recipient and calldata. The attacker selected the GYD token contract itself as the recipient and supplied calldata that invoked its approve function for the attacker's address. After the cross-chain transfer completed, the destination handler executed that calldata against the selected recipient.
This granted the attacker an unlimited GYD allowance, which was then used with transferFrom to withdraw 6,099,337.37 GYD. The token amount and dollar loss are not interchangeable: CertiK traced about $807,000 of extractable liquidity. Gyroscope paused liquidity pools and offered a 33% white-hat bounty; no confirmed recovery is recorded here.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report certik.com
- transaction Transaction arbiscan.io
- analysis CertiK: Gyroscope incident analysis certik.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.