USPD Hack

Reported loss $1.0M
Ethereum
CPIMP deployment attack

What happened

On December 4, 2025, the USPD stablecoin protocol on Ethereum was drained of about $1 million after an attacker who had secretly controlled one of its proxies since deployment activated that control. Reports put the damage at roughly 98 million USPD minted without backing and about 232 stETH taken.

The flaw was in how USPD was deployed, not in the audited contract logic. USPD's deployment script created the StabilizerNFT proxy in one transaction and initialized it in a later one. On September 16, 2025, the attacker used a Multicall3 transaction to get in between those steps, took the admin role and installed a hidden middle contract (a "CPIMP") between the proxy and the real implementation. The middle contract forwarded every call to the legitimate code, kept its own state in custom storage slots, and used manipulated event data and storage slots so that Etherscan showed the genuine implementation. It also restored itself after each transaction, so ordinary upgrades did not remove it.

When USPD attempted a routine upgrade on December 4, the attacker deployed a malicious StabilizerNFT implementation, called upgradeAndCall and drained collateral. USPD said the code had been audited by Nethermind and Resonance before launch. The team paused minting, told users to revoke approvals to the USPD contract, reported the theft to law enforcement and offered the attacker a 10% bounty to return the rest. It later announced a V2 relaunch with atomic deploy-and-initialize and a plan to compensate holders.

**Block data**

  • Attacker: 0x083379BDAC3E138cb0C7210e0282fbC466A3215A
  • Proxy infection tx (Sep 16, 2025): 0xc0b7e490caac2b8cfa5e62d1b28a5e7dba7600e623c71352acbc9b23c2b65b7c
  • Exploit tx (Dec 4, 2025): 0xa7cab072bf0453301a0ab1b06c49a9405d115824fc617fb42cba9b70f3b893c2

How it happened

  1. USPD deployed its StabilizerNFT proxy without initializing it in the same transaction, leaving a gap of a few blocks before initialization.
  2. On September 16, 2025, the attacker used a Multicall3 transaction in that gap to claim admin and install a hidden middle contract between the proxy and the real implementation.
  3. The middle contract forwarded calls to the audited code and reset _initialized, so USPD's own initialization went through and the protocol worked normally. Spoofed events and storage slots made Etherscan show the legitimate implementation.
  4. On December 4, 2025, when USPD attempted an upgrade, the attacker deployed a malicious StabilizerNFT implementation and called upgradeAndCall to drain collateral.
  5. The attacker walked away with roughly $1 million, reported as about 98 million unbacked USPD and about 232 stETH.

Protocol details

Classification Stablecoin / Protocol Logic / Access Control
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol links Website

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.