UXLINK Hack
What happened
On September 22, 2025, UXLINK disclosed a breach of its multisignature wallet infrastructure on Ethereum and Arbitrum. Blockscope traced an initial liquid-asset drain of roughly $12 million, followed by unauthorized token minting and conversions that brought its estimated stolen proceeds to about $41 million.
The multisig delegatecall surface was insufficiently constrained according to the forensic analysis. Because delegatecall ran in the multisig’s authority context, the path could rewrite owner configuration and convert a threshold wallet into attacker-controlled administration.
Case & protocol details
How it happened
- The attacker reached a delegatecall path in the multisig wallet.
- Code executed in the wallet’s storage context changed ownership and threshold settings.
- The attacker became an authorized owner, drained liquid assets and obtained token-mint authority.
- Newly issued UXLINK tokens were sold or bridged; later attacker-side phishing affected some proceeds.
Security review history
- PeckShield Report
Evidence & learning
Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis Website reference binance.com
- analysis UXLink exploit analysis research.blockscope.co
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.