Gyroscope Hack

TOTAL LOST $807K
Low Access Control Attacks arbitrum ethereum

What happened

On 30 January 2026, an attacker exploited Gyroscope's Arbitrum-to-Ethereum GYD bridge. The attacker bridged one wei of GYD to the Ethereum GYD token contract with malicious calldata, creating an unlimited approval that was used to withdraw more than 6 million GYD. CertiK reported that the available liquidity extracted was approximately $807,000.

Technical Root Cause

The bridge allowed arbitrary calldata to execute against a user-chosen recipient, including the GYD token contract. Untrusted cross-chain message data must not be able to create ERC-20 allowances or invoke arbitrary selectors on security-critical recipients.

Case & protocol details

Classification Cross-Chain Bridge / Protocol Logic
Protocol Type Exploit/Other
Official Website www.gyro.finance/
Protocol Twitter/X @GyroStable

Attack Timeline

Gyroscope's bridge accepted a user-supplied destination recipient and calldata. The attacker selected the GYD token contract itself as the recipient and supplied calldata that invoked its approve function for the attacker's address. After the cross-chain transfer completed, the destination handler executed that calldata against the selected recipient.

This granted the attacker an unlimited GYD allowance, which was then used with transferFrom to withdraw 6,099,337.37 GYD. The token amount and dollar loss are not interchangeable: CertiK traced about $807,000 of extractable liquidity. Gyroscope paused liquidity pools and offered a 33% white-hat bounty; no confirmed recovery is recorded here.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.