WUSD.fi Hack

TOTAL LOST $207K
Low Flash Loan Attacks ethereum

What happened

On May 25, 2026, the WUSD.fi / GLOVE incentive program on Ethereum was exploited for approximately $207,000. The stolen liquidity was subsequently swapped for roughly 98 ETH and laundered via the Railgun privacy protocol.

The vulnerability was a classic sybil abuse flaw within the protocol's reward distribution logic. The WUSD._englove function allowed any address that wrapped at least 100 WUSD,  while holding fewer than 2 GLOVE, to mint up to 2 GLOVE tokens. Because the protocol lacked sybil resistance, the attacker used EIP-7702 helper contracts and Morpho flash loans to automate the creation of numerous fresh addresses.

This allowed them to repeatedly execute wrap/unwrap cycles to harvest GLOVE tokens at scale. The attacker then dumped the farmed GLOVE into Uniswap V3 liquidity pools, draining the underlying USDC and USDT reserves before swapping the proceeds for ETH.

Exploiter EOA: 0x88329A09…5a57f8

Exploit Transaction: 0x2051c1f8…b37712

Case & protocol details

Classification Other / Protocol Logic
Protocol Type Exploit/Flash Loan Attack
Smart Contract Language Solidity
Official Website usd.ai/
Protocol Twitter/X @USDai_Official

Evidence & learning

Proof of concept

1 available

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.