ChainBleedv0.1 · open intel
← back to feed·PHISHING2025-12-04 · 6mo ago
Incident · SLOWMIST

USPD

"CPIMP" (Clandestine Proxy In the Middle of Proxy) attack
Estimated loss
$1.00M
VERDICT —OUT OF SCOPE
Root cause is phishing — victims signed malicious transactions or approvals off-protocol. Contract logic was not the failure surface; user-side wallet hygiene was. Pre-deployment audit cannot catch this class.
▰ METHOD
PHISHING
PHISHING
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

According to PeckShieldAlert, the stablecoin project USPD has suffered a major security breach, resulting in approximately $1 million in losses. The USPD team later confirmed that the protocol had been exploited, with the attacker minting tokens without authorization and draining liquidity. The official team has urgently advised users to revoke all token approvals granted to the USPD contract. According to the project’s confirmation, the incident was identified as a “CPIMP” attack. During the deployment phase, the attacker used Multicall3 to preemptively initialize the proxy and seize administrator privileges, while disguising the malicious implementation as an audited contract. The hidden logic remained dormant for several months before being activated, allowing the attacker to upgrade the proxy, mint approximately 98 million USPD tokens, and transfer around 232 stETH. The USPD team has disclosed the attacker addresses (Infector: 0x7C97…9d83, Drainer: 0x0833…215A) and stated that they are working with law enforcement and white-hat partners to trace the funds. The team has also offered a 10% bounty if the attacker returns the stolen assets. Attack method (per SlowMist): "CPIMP" (Clandestine Proxy In the Middle of Proxy) attack. Reported loss: $ 1,000,000.

Primary source
https://x.com/PeckShieldAlert/status/1996826080741937213
Sourced from
slowmist
Technical record
chain
protocol
USPD
bug_class
phishing
date_occurred
2025-12-04
loss_usd
$1,000,000
source_id
sm:uspd::2025-12-04
Related — same bug class· phishing
2026-04-29
1mo ago
Sweat Foundation
Contract Vulnerability
phishing
$3.50M
OUT OF SCOPE
2026-04-28
1mo ago
ETH
Multicall yvETH Approval Abuse (victim 0x9828)
Approval-drainer via multicall aggregator (phishing pattern)
phishing
$980.1K
OUT OF SCOPE
2026-04-27
1mo ago
ETH
Unverified Contract 0x2990A16D
Stale approval drain on unverified contract
phishing
$229.0K
OUT OF SCOPE
2026-04-03
2mo ago
Adobe
Supply Chain Attack
phishing
OUT OF SCOPE
2026-04-02
2mo ago
Trust Wallet
Infrastructure Hijacking
phishing
OUT OF SCOPE
2025-11-11
7mo ago
Polymarket
Phishing attack
phishing
$500.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence