Moby Hack

Reported loss $1.5M
Arbitrum
Private Key Compromised (Unknown Method)

What happened

On January 8, 2025, Moby Trade, an options protocol on Arbitrum, lost about $2.5 million after an attacker obtained a leaked private key that controlled its proxy contracts. The attacker upgraded the contracts and used the emergencyWithdrawERC20 function to pull USDC, WETH and WBTC from LP assets.

The attacker's own replacement contract had an unprotected upgrade function. MEV researcher Tony Ke's bot used that flaw to run the same attack against the attacker and rescued about $1.47 million in USDC, which was returned to the protocol. Rekt credits the rescue to SEAL 911 with Ke leading. The rescuers missed the WETH and WBTC by about 30 seconds, so roughly 207.78 WETH and 3.774 WBTC (about $1.0 million) stayed with the attacker and were bridged out.

Moby said the incident was a key leak rather than a flaw in its smart contracts. Deposits and withdrawals were closed after the attack and stayed shut while Moby investigated. Moby said OLP depositors would be able to withdraw with treasury backing and offered compensation to options traders.

How it happened

  1. The attacker obtained a private key with admin control over Moby's upgradeable proxy contracts. How the key leaked has not been published.
  2. Using that key, the attacker upgraded the proxies to a malicious implementation.
  3. The attacker called emergencyWithdrawERC20 to withdraw USDC, WETH and WBTC from LP assets.
  4. The attacker's contract left its own upgrade function unprotected. Tony Ke's bot used it to take about $1.47 million in USDC back, and those funds went back to Moby.
  5. About 207.78 WETH and 3.774 WBTC (about $1.0 million) could not be rescued in time and were bridged from Arbitrum to Ethereum.

Protocol details

Classification Infrastructure / Key Compromise / Exchange (DEX)
Protocol Type Options
Implementation language Solidity
Protocol links Website @Moby_trade

Funds Recovery

100.0%

Recovered

$1.5M

Net Loss

$0

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.