Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Aurellion Labs Drained of $455K USDC in Diamond Proxy Exploit

The vulnerability underscores a common pitfall in Ethereum-based diamond architecture (EIP-2535), where initialization logic must be rigorously protected across all ownership assignment routes.

Written By:
Gopal Solanky

Last updated: 27 minutes ago
Published 35 minutes ago
Share
Last updated: 27 minutes ago
Published 35 minutes ago
Aurellion Labs Drained of $455K USDC in Diamond Proxy Exploit

Aurellion Labs, a decentralized finance project on Arbitrum, lost approximately $455,003 USDC in a targeted smart contract attack on Tuesday, according to blockchain security firm SlowMist. 

The incident highlights persistent risks in complex contract architectures like diamond proxies, even as the sector pushes for more sophisticated designs. 

The attacker, operating from address 0x9f4…d5ca, exploited an unprotected initialize(address) function in the SafeOwnable Facet of the project’s diamond proxy contract at 0x0adc…f1b2. 

According to SlowMist’s analysis, the contract allowed ownership to be set through a non-initialization path that failed to update the _initialized storage slot. This oversight left the door open for re-initialization.

🚨SlowMist TI Alert🚨

💸 @Aurellion_Labs Loss: 455,003 USDC (~$455,003)

🔍 Root Cause: Unprotected initialize(address varg0) in SafeOwnable Facet. Diamond set owner via non-initialize path without updating _initialized version slot (bytes 0-7 of 0xf0c57e…) from 0,…

— SlowMist (@SlowMist_Team) May 12, 2026

Once in control, the attacker called diamondCut to inject a malicious facet containing a pullERC20 function. This enabled the rapid drainage of approved USDC tokens from multiple victim wallets. 

The vulnerability underscores a common pitfall in Ethereum-based diamond architecture (EIP-2535), where initialization logic must be rigorously protected across all ownership assignment routes. 

Security researchers have repeatedly warned that incomplete protection of initializer functions can lead to ownership hijacks, especially in proxy-based systems that rely on facets for modularity. 

As of now, Aurellion Labs has not issued an official statement on the breach or confirmed any recovery efforts. The stolen funds, valued at roughly $455,000 at the time of the exploit, represent a significant hit for the project. 

This latest incident adds to a growing list of DeFi exploits in 2026, where attackers continue to target subtle logic flaws rather than flashy code bugs. 

This is a developing story and more information will be added as the event unfolds. 

Also read: DOJ Indicts Tennessee Trio for Armed $6.5M Crypto Theft in California

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

How the TXEX and DSJ Syndicates Built a $150M Empire on Trafficked Labor and Fabricated Lives
How the TXEX and DSJ Syndicates Built a $150M Empire on Trafficked Labor and Fabricated Lives
Ex-Goliath Ventures CEO Apologizes as $328M Crypto Scam Charges Mount
Ex-Goliath Ventures CEO Apologizes as $328M Crypto Scam Charges Mount
Bitcoin’s Biggest Corporate Backer Sees CLARITY Act as Game-Changing Moment
Bitcoin’s Biggest Corporate Backer Sees CLARITY Act as Game-Changing Moment
CLARITY Act Hits Labor Wall 2 Days Before Senate Committee Vote
CLARITY Act Hits Labor Wall 2 Days Before Senate Committee Vote
Telcoin (TEL) Surges 27% in 24 Hours Amid Broader Altcoin Rally
Telcoin (TEL) Surges 27% in 24 Hours Amid Broader Altcoin Rally

Find Us on Socials

You may also like

Ondo Finance Surpasses $1B TVL in Tokenized Stocks and ETFs

Ondo Finance Surpasses $1B TVL in Tokenized Stocks and ETFs

CIP-86 Passed: CoW DAO Begins Compensation for April Attack

CIP-86 Passed: CoW DAO Begins Compensation for April Attack

Multi-Chain Wallet Breach Drains $665K Across 50+ Victims Cluster

Multi-Chain Wallet Breach Drains $665K Across 50+ Victims Cluster

Fake TronLink Extension Targets TRON Users in Phishing Scam

Fake TronLink Extension Targets TRON Users in Phishing Scam

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information