Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Zcash vs. Monero The 2026 Privacy Coin War Just Got Decided in One Week
    Zcash vs. Monero: The 2026 Privacy Coin War Just Got Decided in One Week
    MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
    MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
  • Opinion
    OpinionShow More
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

USPD Exploiter Remained Silent for 78 Days After Proxy Takeover

A patched vulnerability, a 78-day silent infiltration, and $1M in unbacked tokens minted, USPD now faces one of 2025’s most alarming DeFi failures

Written By:
Thales Rodrigues

Reviewed By:
Gopal Solanky

Last updated: December 10, 2025 11:44 PM
Published 2025-12-10
Share
Last updated: December 10, 2025 11:44 PM
Published 2025-12-10
USPD Exploiter Remained Silent for 78 Days After Proxy Takeover

Key Highlights

  • An attacker front-ran USPD’s proxy initialization on September 16 and held admin access for 78 days.
  • The exploit used CPIMP, a known vulnerability patched industry-wide in July.
  • USPD now plans V2, recovery pools, and user restitution as the investigation continues.

New findings reveal that the USPD stablecoin protocol suffered a major security breach that allowed an attacker to control its proxy contract for nearly three months, minting $1 million in unbacked tokens and draining protocol reserves. Rekt’s December 8 analysis shows the exploit came from a deployment-phase flaw that the industry had already patched months earlier.

The attacker exploited a narrow time window during USPD’s September 16 deployment, gaining admin rights before the protocol’s legitimate initialization was executed. A hidden proxy forwarded calls to the audited code, allowing normal operations while the attacker controlled the protocol.

24-second window leads to 78-day breach

As per Rekt’s analysis, the exploit hinged on USPD deploying its proxy and initializing it in separate transactions. Within 24 seconds of proxy deployment, the attacker front-ran the pending initialization, seizing admin privileges and embedding a “shadow” implementation.

The protocol functioned flawlessly for 78 days. Audits from Nethermind and Resonance confirmed the code was sound, but auditors never saw the malicious proxy injected during deployment. On December 4, the attacker struck: upgrading the proxy to malicious logic, minting 98 million USPD, draining 232 stETH, and converting roughly $300,000 into USDC.

Remaining funds, about $1 million, continue to sit in the attacker’s wallet, untouched.

The CPIMP vulnerability strikes again

The attack used CPIMP (Clandestine Proxy in the Middle of Proxy), a vulnerability security team patched across dozens of protocols during a July emergency effort. Firms like Dedaub, Venn Security, and SEAL 911 coordinated a 36-hour sweep that saved more than $10 million in assets.

According to Rekt’s breakdown, however, USPD has never applied the recommended safeguards. While the audits certifying its logic were valid, the lack of atomic deployment left the front door open. Researchers argue the breach was preventable, as the same attack vector had compromised Kinto earlier this year.

7/ To the Attacker:
We are willing to view this as a whitehat rescue.

If you return the funds (minus a standard 10% bug bounty), we will cease all law enforcement actions and consider this matter resolved.

Contact us immediately on any channel you wish, or simply return 90% of…

— USPD.IO | The Dollar of the Decentralized Nation (@USPD_io) December 4, 2025

USPD offered a 10% bounty for fund recovery, but December 8 activity shows some stolen ETH already routed through Tornado Cash.

Protocol’s bounce back

USPD plans to launch a rebuilt V2 in Q2 2026, introduce recovery pools funded by protocol revenue, and issue claim tokens to affected users. The team has also opened a private channel for the 230 impacted addresses.

Despite the exploit, the USPD stablecoin has maintained its dollar peg, though liquidity is down significantly. The protocol insists that no flaws existed in its smart contract logic, only in the handling of deployment.

The incident is poised to become a case study in DeFi risk management: audits alone are not enough, deployment must be secured, and known vulnerabilities cannot be ignored.

Also read: Hacker Exploits Binance Co-CEO’s WeChat to Pump Mubarakah Token

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Stablecoin
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Thales Rodrigues- Crypto Journalist
By Thales Rodrigues
Follow:
Thales is a Brazilian economist passionate about marketing, bringing with him experience from the country’s largest banks and financial institutions. Outside of work, he dedicates his time to sports, family, and business studies.
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

India Arrests 2 More Suspects in ₹226 Cr Crypto Terror Financing Case
India Arrests 2 More Suspects in ₹226 Cr Crypto Terror Financing Case
House Whip Emmer Meets CFTC Chair to Push CLARITY Act
House Whip Emmer Meets CFTC Chair to Push CLARITY Act
Rep. French Hill Defends CLARITY Act Amid Banking Industry Concerns
Rep. French Hill Defends CLARITY Act Amid Banking Industry Concerns
Congress Reveals First Detailed Look at Strategic Bitcoin Reserve
Congress Reveals First Detailed Look at Strategic Bitcoin Reserve
SpaceX IPO Hype Hits Kraken as SPCXx Token Access Opens
SpaceX IPO Hype Hits Kraken as SPCXx Token Access Opens

Find Us on Socials

You may also like

Cypherpunk Says ‘Zero Evidence of a Hack’ After Zcash's 50% Drop

Cypherpunk Says ‘Zero Evidence of a Hack’ After Zcash’s 50% Drop

Senator Lummis Says CLARITY Act Can Clear 60 Votes Despite Banks

Senator Lummis Says CLARITY Act Can Clear 60 Votes Despite Banks

Crypto Market Today Ethereum Crashes Below $1,600, Bitcoin Tests $60K, XRP Nears $1.10

Crypto Market Today: Ethereum Crashes Below $1,600, Bitcoin Tests $60K, XRP Nears $1.10

Ethereum ETFs End 17-Day Outflow Streak as BlackRock Leads Return

Ethereum ETFs End 17-Day Outflow Streak as BlackRock Leads Return

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information