UXLINK Hack

REPORTED LOSS $48.0M
High Delegatecall Exploit arbitrum ethereum

What happened

On September 22, 2025, UXLINK disclosed a breach of its multisignature wallet infrastructure on Ethereum and Arbitrum. Blockscope traced an initial liquid-asset drain of roughly $12 million, followed by unauthorized token minting and conversions that brought its estimated stolen proceeds to about $41 million.

Technical Root Cause

The multisig delegatecall surface was insufficiently constrained according to the forensic analysis. Because delegatecall ran in the multisig’s authority context, the path could rewrite owner configuration and convert a threshold wallet into attacker-controlled administration.

Case & protocol details

Classification Protocol Logic / Other / Access Control
Protocol Type SoFi
Implementation language Solidity
Official Website www.uxlink.io/
Protocol Twitter/X @UXLINKofficial

Market Context at Time of Hack

Token Price at Hack $0.3221
Market Cap at Hack $154.5M
Reported loss / token market cap 31.06%
Token Categories
SocialFi Ethereum Ecosystem

How it happened

  1. The attacker reached a delegatecall path in the multisig wallet.
  2. Code executed in the wallet’s storage context changed ownership and threshold settings.
  3. The attacker became an authorized owner, drained liquid assets and obtained token-mint authority.
  4. Newly issued UXLINK tokens were sold or bridged; later attacker-side phishing affected some proceeds.

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.