Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

IPOR’s Fusion PlasmaVault Hit by $336K Exploit via EIP-7702 Flaw

Attackers exploited a legacy smart contract flaw involving EIP-7702 to drain $336,000 USDC, subsequently laundering it through Tornado Cash.

Written By Jalpa Bhavsar
Fact Checked by Divya Mistry
Published 2026-01-07
Make The Crypto Times preferred on GoogleGoogle
IPOR’s Fusion PlasmaVault Hit by $336K Exploit via EIP-7702 Flaw

Key Highlights

  • The Fusion PlasmaVault hack happened due to a smart contract flaw that let attackers run unauthorized code.
  • On January 6, 2026, nearly $267,000 was stolen and moved through an external wallet to Tornado Cash.
  • The attacker used a malicious “fuse” contract to quickly redirect all vault assets by exploiting the smart contract itself.
  • An old PlasmaVault flaw let an attacker steal $336,000 USDC in total, which IPOR said will be paid back to affected users.

Blockchain security monitors have highlighted suspicious transactions in relation to the Fusion Plasma Vault contract, part of the IPOR (Inter Protocol Offered Rate) ecosystem.

This event was first identified by SlowMist’s MistEye solution, which picked up on some suspicious activity related to this contract. Blockchain security company CertiK also later issued alerts pointing to unusual transactions.

🚨SlowMist TI Alert🚨

MistEye has detected potential suspicious activities related to @ipor_io. The root cause is that the underlying contract delegated by the EOA account controlled by the project team through EIP-7702 contains a vulnerability that allows arbitrary external… pic.twitter.com/hAxh4LRpkv

— SlowMist (@SlowMist_Team) January 7, 2026

Researchers identified that the technical flaw enabled a malicious user to transfer money while displaying a normal transaction process. The incident highlights the risks hidden in complex smart contracts.

This problem arose from a contract written using EIP-7702, which is a functionality that allows an externally owned account to delegate control to a smart-contract-controlled account. Here, the delegate contract allowed arbitrary external calls, giving the attacker freedom to run malicious code.

Around $267,000 moved in one transaction

In the case that came to light on January 6, 2026, during the withdrawal process, an exploit contract illicitly took advantage of the vulnerability and drained the assets worth almost $267,000.

#CertiKInsight 🚨

We have detected suspicious transactions on the @ipor_io PlasmaVault contract.https://t.co/kCwakhzXmC

During a withdraw call, the 'fuse' contract, configured a few seconds prior, transferred all funds (~$267K) to EOA 0x9b1b, who then bridged the funds to… pic.twitter.com/RF85VQIKDM

— CertiK Alert (@CertiKAlert) January 7, 2026

These funds were initially routed to an outside wallet (0x9b1b…), and later bridged from the Arbitrum platform to Ethereum, eventually being deposited on the Tornado Cash platform. Although the utilization of such platforms is not prohibited, the matter makes tracing rather difficult.

What went wrong

IPOR’s post-mortem shows the incident happened because two problems came together. The affected PlasmaVault was an older vault that did not properly check “fuses,” which are logic modules used during withdrawals. At the same time, an administrator account was using an EIP-7702 delegation setup.

🚨 Security Update: IPOR USDC Fusion Optimizer on Arbitrum Vault Exploit

The IPOR team was alerted on January 6th by @hexagate_ and @blockaid_ regarding a malicious transaction. Following a swift investigation, we have identified an exploit resulting in a loss of $336K USDC.… https://t.co/brS0MfQ7Mu

— Fusion (by IPOR) (@ipor_io) January 7, 2026

The delegated contract allowed arbitrary external calls. This made it possible for an attacker to act as if they were the administrator, add a malicious fuse, and trigger a withdrawal that ran harmful code. In simple terms, the vault trusted unsafe logic and ended up executing instructions that moved funds out.

IPOR said this exact setup only existed in this legacy vault. Newer Fusion vaults already include stricter validation rules that would prevent this type of attack.

While on-chain data shows about $267,000 was drained initially, IPOR later confirmed total losses of around $336,000 USDC. The team is working with security firms, including Security Alliance, to trace and recover the funds. Affected users will be reimbursed from the DAO treasury, and no other Fusion vaults were impacted.

Industry context and regulatory response

Using privacy tools like Tornado Cash to move stolen crypto is not new. In 2025, the 10 largest hacks saw roughly $2.2 billion in losses, with several involving mixers, according to data from PeckShield.

A recent example involved a compromised multisig wallet. The attacker stole $27.3 million, withdrew 1,000 ETH ($3.24 million) from Aave, and laundered it through Tornado Cash. So far, they have deposited 6,300 ETH ($19.4 million) and hold a leveraged position of $20.5 million in ETH.

Regulators are taking notice. In South Korea, authorities are proposing bank-level liability rules for exchanges after a $32 million hack at Upbit. Exchanges may be required to compensate users for losses, and fines for hacked platforms could reach 10% of losses.

Lessons for DeFi users

What the PlasmaVault hack illustrates is that the attackers are now targeting vulnerabilities in the code of the smart contract itself rather than the user account. Small bugs in code can result in significant losses. Transferring money between chains makes it difficult to follow the money trail with the help of tools such as Tornado Cash.

For everyday DeFi users, the case serves as a reminder to take security alerts seriously and remain cautious around new features and upgrades. Unusual on-chain activity can often be the first warning sign.

Also Read: Crypto Hacker Makes $1 Million Trading Bitcoin

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email
Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Central Bureau of Investigation India emblem mounted on a stone wall.
CBI Warns Indian Crypto Users Over P2P Trades and UPI Payments

Find Us on Socials

You may also like

Zentra Finance logo on a soft orange and white gradient background.

Zentra Finance Reports $143K Exploit Affecting ctUSD Reserve

Person holding a smartphone displaying the Zcash logo and text.

Zcash Holder Says $589K USDT Stuck on NEAR Intents 50 Days After Zodl Swap

Smartphone displaying the orange Metaplanet logo against an orange background.

Metaplanet Shares Fall 3.86% as Firm Proposes ¥27.8B Capital Cut & Hong Kong Unit

Hooded figure in dark clothing sitting behind a laptop screen with the green octopus logo and text for "Symbiosis" illuminated in the background

Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information