An Ekubo Protocol user lost roughly $1 million in WBTC after attackers exploited an approval / allowance bug in Ekubo’s EVM swap router, draining funds from wallets that had previously granted token permissions to the router contracts. Security firm Blockaid attributed the incident to a payment-callback bug in Ekubo’s v2 EVM extension contracts, where the router accepted payer parameters from untrusted calldata and could pull tokens from users based on existing approvals without appropriate checks. One address reportedly lost around 17 WBTC, making up the majority of the roughly $1.4 million total drained across about 85 transactions, with the attacker later sending funds through Tornado Cash. Ekubo is primarily a Starknet-based automated market maker (AMM), but the exploit affected only its Ethereum EVM router contracts, not the core Starknet deployment or its principal liquidity pools. Ekubo stated that the “protocol is safe to use” and clarified that the incident was confined to these router contracts on Ethereum, emphasizing that Starknet contracts and main protocol logic remained intact. Nonetheless, the project urged users—especially those who interacted with Ethereum V2/V3 and Arbitrum V3 routers—to revoke existing token approvals, underscoring the broader DeFi risk posed by stale or unlimited ERC‑20 allowances that can be abused when router or extension logic has flaws. The case has intensified calls for routine approval hygiene, more rigorous auditing of router and extension contracts, and improved wallet tooling to monitor and manage token permissions across chains.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Smart Contract

Comments