Moby Trade Hack
What happened
On January 8, 2025, Moby Trade suffered a $2.5 million hack on the Arbitrum network due to a compromised private key, which allowed an attacker to upgrade the protocol’s smart contract and execute unauthorized withdrawals. However, white hat hacker Tony Ke exploited a flaw in the attacker's contract and successfully recovered $1.5 million, reducing total losses to $1 million.
The attack stemmed from a leaked private key controlling Moby Trade’s proxy contract, enabling the attacker to modify the smart contract and use the emergencyWithdrawERC20 function to steal USDC, WETH, and WBTC. The attacker swapped the stolen funds into ETH and transferred them to external addresses. However, Tony Ke, an MEV researcher, identified an oversight in the attacker's contract—a missing access control mechanism on the upgrade function.
Using this vulnerability, Ke executed a counter-exploit to retrieve $1.5 million in USDC, which was returned to the protocol. Unfortunately, the remaining $1 million in WETH and WBTC could not be recovered in time. In response, Moby Trade suspended operations and assured users of compensation while investigating the breach.
Case & protocol details
Funds Recovery
Recovered
$1.5M
Net Loss
$1,000,000
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report halborn.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.