ChainBleedv0.1 · open intel
← back to feed·ETHEXTERNAL-CALL2026-01-06 · 5mo ago
Incident · SLOWMIST

Fusion by IPOR

Contract Vulnerability
Estimated loss
$336.0K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
EXTERNAL CALL
EXTERNAL-CALLBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Fusion has released a security update stating that its IPOR USDC Fusion Optimizer contains a vulnerability in the Arbitrum Vault. The IPOR team was notified and confirmed on January 6 that the vulnerability had resulted in a loss of approximately $336,000 USDC. This exploit only affected a specific older version of the Fusion Vault, and due to its unique configuration, it was the only vault susceptible to this particular attack vector. According to further analysis by SlowMist, the root cause of the incident lies in the underlying contract delegated by the EOA account controlled via EIP‑7702, which contained a security flaw allowing arbitrary external calls. The attacker exploited this flaw to create and configure a malicious circuit-breaker contract targeting the Plasma Vault, thereby illicitly extracting funds from the vault. The official statement noted that the loss represents less than 1% of the total funds secured by Fusion. The team is currently working with Security Alliance to track the funds and attempt recovery. IPOR DAO will cover the deficit from its treasury, and all affected depositors will receive full compensation. Additionally, according to CertiK, approximately $267,000 of the stolen funds have been cross‑chain transferred to the Ethereum network and subsequently moved into Tornado Cash. On January 7, the IPOR team announced on X that the funds have been recovered, and a 10% bounty agreement has been reached with the white-hat party, which will be covered by the IPOR DAO. The incident has now been concluded as a good-faith white-hat security event. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 336,000.

Primary source
https://x.com/ipor_io/status/2008728627190321480
Sourced from
slowmist
Technical record
chain
ethereum
protocol
Fusion by IPOR
bug_class
external-call
date_occurred
2026-01-06
loss_usd
$336,000
source_id
sm:fusion-by-ipor::2026-01-06
Related — same bug class· external-call
2026-04-27
1mo ago
ZetaChain
Contract Vulnerability
external-call
$334.0K
UNRATED
2026-01-26
4mo ago
ETH
SwapNet
Contract Vulnerability
external-call
$16.80M
UNRATED
2025-09-27
8mo ago
Hyperdrive
Contract Vulnerability
external-call
$782.0K
UNRATED
2024-08-28
1y ago
Aave
Contract Vulnerability
external-call
$56.0K
UNRATED
2024-07-23
1y ago
Spectra
Contract Vulnerability
external-call
$550.0K
UNRATED
2024-04-23
2y ago
Magpie Protocol
Contract Vulnerability
external-call
$129.0K
UNRATED
ChainBleed — live web3 threat intelligence