Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Aurellion Labs Drained of $455K USDC in Diamond Proxy Exploit

The vulnerability underscores a common pitfall in Ethereum-based diamond architecture (EIP-2535), where initialization logic must be rigorously protected across all ownership assignment routes.

Written By Gopal Solanky
Published 2026-05-12·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Aurellion Labs Drained of $455K USDC in Diamond Proxy Exploit
Show AI Summary
DeFi project vulnerabilities persist due to complex contract designs
Smart contract attacks increasingly target subtle logic flaws over code bugs
Industry losses mount as exploiters continue to find weaknesses in proxy-based systems

Aurellion Labs, a decentralized finance project on Arbitrum, lost approximately $455,003 USDC in a targeted smart contract attack on Tuesday, according to blockchain security firm SlowMist. 

The incident highlights persistent risks in complex contract architectures like diamond proxies, even as the sector pushes for more sophisticated designs. 

The attacker, operating from address 0x9f4…d5ca, exploited an unprotected initialize(address) function in the SafeOwnable Facet of the project’s diamond proxy contract at 0x0adc…f1b2. 

According to SlowMist’s analysis, the contract allowed ownership to be set through a non-initialization path that failed to update the _initialized storage slot. This oversight left the door open for re-initialization.

🚨SlowMist TI Alert🚨

💸 @Aurellion_Labs Loss: 455,003 USDC (~$455,003)

🔍 Root Cause: Unprotected initialize(address varg0) in SafeOwnable Facet. Diamond set owner via non-initialize path without updating _initialized version slot (bytes 0-7 of 0xf0c57e…) from 0,…

— SlowMist (@SlowMist_Team) May 12, 2026

Once in control, the attacker called diamondCut to inject a malicious facet containing a pullERC20 function. This enabled the rapid drainage of approved USDC tokens from multiple victim wallets. 

The vulnerability underscores a common pitfall in Ethereum-based diamond architecture (EIP-2535), where initialization logic must be rigorously protected across all ownership assignment routes. 

Security researchers have repeatedly warned that incomplete protection of initializer functions can lead to ownership hijacks, especially in proxy-based systems that rely on facets for modularity. 

As of now, Aurellion Labs has not issued an official statement on the breach or confirmed any recovery efforts. The stolen funds, valued at roughly $455,000 at the time of the exploit, represent a significant hit for the project. 

This latest incident adds to a growing list of DeFi exploits in 2026, where attackers continue to target subtle logic flaws rather than flashy code bugs. 

This is a developing story and more information will be added as the event unfolds. 

Also read: DOJ Indicts Tennessee Trio for Armed $6.5M Crypto Theft in California

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackStablecoin
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Binance-Backed SafePal Data Leak Sparks Phishing Fears for 40K Buyers
Binance-Backed SafePal Data Leak Sparks Phishing Fears for 40K Buyers
Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%
Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%
Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M
Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M
Tether CEO Denies Blockchain Plans as Stablecoin Operations Grow
Tether CEO Denies Blockchain Plans as Stablecoin Operations Grow

Find Us on Socials

You may also like

BitGo Takes Lead in $26.6B Real-World Asset Market With 27.5% Share

BitGo Takes Lead in $26.6B Real-World Asset Market With 27.5% Share

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

OCC Clears Trump-Backed World Liberty Trust Bank to Take Over USD1 From BitGo

OCC Clears Trump-Backed World Liberty Trust Bank to Take Over USD1 From BitGo

StablecoinX Holds 31% of ENA Circulating Supply, Reports $34.2M Loss

StablecoinX Holds 31% of ENA Circulating Supply, Reports $34.2M Loss 

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information