IPOR Fusion Hack
What happened
On January 6, 2026, a legacy IPOR Fusion USDC Optimizer vault on Arbitrum was exploited for approximately $336,000 USDC. IPOR's post-mortem says the issue was isolated to a specific legacy vault configuration and did not affect newer Fusion vaults. IPOR DAO committed to reimburse affected depositors.
The legacy vault's instant-withdrawal configuration did not validate fuse modules strictly, while an administrator had delegated authority to an arbitrary-call-capable contract. Together these conditions allowed attacker-controlled withdrawal logic to be installed and executed.
Case & protocol details
How it happened
An administrator EOA delegated execution through EIP-7702 to a contract with arbitrary-call capability. The attacker used that delegated authority to add a malicious fuse to the legacy vault, then triggered instantWithdraw so the fuse could transfer vault assets out.
Funds Recovery
Recovered
$336K
Net Loss
$0
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.