Moby Trade Hack

REPORTED LOSS $2.5M
Medium Access Control

What happened

On January 8, 2025, Moby Trade suffered a $2.5 million hack on the Arbitrum network due to a compromised private key, which allowed an attacker to upgrade the protocol’s smart contract and execute unauthorized withdrawals. However, white hat hacker Tony Ke exploited a flaw in the attacker's contract and successfully recovered $1.5 million, reducing total losses to $1 million.

The attack stemmed from a leaked private key controlling Moby Trade’s proxy contract, enabling the attacker to modify the smart contract and use the emergencyWithdrawERC20 function to steal USDC, WETH, and WBTC. The attacker swapped the stolen funds into ETH and transferred them to external addresses. However, Tony Ke, an MEV researcher, identified an oversight in the attacker's contract—a missing access control mechanism on the upgrade function.

Using this vulnerability, Ke executed a counter-exploit to retrieve $1.5 million in USDC, which was returned to the protocol. Unfortunately, the remaining $1 million in WETH and WBTC could not be recovered in time. In response, Moby Trade suspended operations and assured users of compensation while investigating the breach.

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Access control
Official Website app.moby.trade/
Protocol Twitter/X @Moby_trade

Funds Recovery

60.0%

Recovered

$1.5M

Net Loss

$1,000,000

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.