Usual Hack
Incident Overview
On May 27, 2025, Usual's USD0++ Investment Vault was exploited through an arbitrage opportunity, leading to a $43,000 loss from the vault itself. The main protocol remained unaffected, with no user funds lost and no pause on the Usual Core Protocol.
The exploit stemmed from a capped mechanism used to unwrap USD0++ into USD0 during deposits into the investment vault. The attacker manipulated this limitation to arbitrage the conversion process, extracting $43,000 from the vault. Since only the vault’s internal funds were impacted and user balances remained untouched, the protocol confirmed that the exploit did not compromise user safety. The affected vault has been isolated and will be reenabled after mitigation steps are implemented.
Tx:
https://etherscan.io/tx/0x585d8be6…f271f8
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Usual, these are the critical security checks that could have prevented this incident (May 2025).
- Verify all logic paths related to Arbitration Exploit / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialProof-of-Concept Exploits
On-Chain Evidence & References
- Twitter/X Alert https://x.com/BlockSecTeam/status/1927601457815040283
Sources & References
- 01
- 02
Learn to Prevent the Next Usual
The Usual hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.