Skip to content

Hackers Drain $2.5M from Arcadia Finance on Base Blockchain – Here’s What Happened

2025-07-15 10:58:08

Hackers Drain $2.5M from Arcadia Finance on Base Blockchain – Here’s What Happened

Main Idea

Hackers exploited a vulnerability in Arcadia Finance's Rebalancer contract on the Base blockchain, stealing approximately $2.5 million in cryptocurrency, marking the platform's second major security incident.

Key Points

1. The attackers drained user vaults, primarily stealing 2.3 million USDC and 227,000 USDS, by exploiting a vulnerability in the Rebalancer contract.

2. The exploit began with funding through Tornado Cash on Ethereum, followed by a bridging operation to Base, and the attack was executed within minutes of deploying the malicious contract.

3. Arcadia Finance acknowledged the breach and advised users to remove permissions for asset managers, while blockchain security firm Hacken identified the vulnerability as improper validation of swapData parameters.

4. This incident follows a previous $455,000 hack in October 2023, highlighting ongoing security concerns in the DeFi ecosystem.

5. CertiK reports over $2.47 billion in losses from 344 DeFi incidents in the first half of 2025, with wallet-related breaches and phishing scams being major contributors.

Description

Hackers exploited a vulnerability in Arcadia Finance’s Rebalancer contract on Tuesday, draining approximately $2.5 million in cryptocurrency from the decentralized finance platform operating on Base blockchain. The attackers manipulated arbitrary swapData parameters to execute unauthorized swaps that emptied user vaults, according to blockchain security firm Hacken . The stolen funds, consisting primarily of 2.3 million USDC and 227,000 USDS tokens, were swapped to Wrapped Ethereum and bridged t...

>> go to origin page