IPOR Fusion Hack

REPORTED LOSS $336K
Low EIP-7702 Delegated Authority Arbitrum

What happened

On January 6, 2026, a legacy IPOR Fusion USDC Optimizer vault on Arbitrum was exploited for approximately $336,000 USDC. IPOR's post-mortem says the issue was isolated to a specific legacy vault configuration and did not affect newer Fusion vaults. IPOR DAO committed to reimburse affected depositors.

Technical Root Cause

The legacy vault's instant-withdrawal configuration did not validate fuse modules strictly, while an administrator had delegated authority to an arbitrary-call-capable contract. Together these conditions allowed attacker-controlled withdrawal logic to be installed and executed.

Case & protocol details

Classification Protocol Logic / Yield Aggregator
Protocol Type Exploit/Access control
Implementation language Solidity
Official Website app.ipor.io/
Protocol Twitter/X @ipor_io

How it happened

An administrator EOA delegated execution through EIP-7702 to a contract with arbitrary-call capability. The attacker used that delegated authority to add a malicious fuse to the legacy vault, then triggered instantWithdraw so the fuse could transfer vault assets out.

Funds Recovery

100.0%

Recovered

$336K

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.