Brahma Hack
Check if your address is affected.
Brahma is a DeFi project that in 2022 offered yield vaults, including a vault called TopGear that was built on the lending protocol Gearbox. To make deposits easier, Brahma offered a helper contract, called a zapper, that users approved to spend their USDC. On 9 November 2022, an attacker found that this zapper did not properly check the instructions it was given. That meant anyone could tell it to move tokens out of any wallet that had approved it, not just their own.
The attacker used the flaw to take around $90k of USDC from wallets on Ethereum that had approved the zapper, and later swapped the stolen USDC into DAI. Security firms flagged the attack soon after, and QuillAudits urged anyone who had used the contract to revoke their approvals right away. It is not clear whether Brahma compensated the users who lost funds.
Contracts on a blockchain cannot simply be deleted, so any approval to this zapper stays active until you remove it yourself. If you ever deposited into Brahma's TopGear vault, check your approvals on Ethereum and revoke any that remain for this contract, especially for USDC. Revoking protects the tokens that are still in your wallet, but it does not bring back funds that were already taken.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →