Concentric Hack
Check if your address is affected.
Concentric was a liquidity manager on Arbitrum. Its vaults automatically managed users' liquidity positions on decentralized exchanges, adjusting their price ranges over time, and users approved these vaults to move their tokens when depositing. On 22 January 2024, an attacker took control of the wallet that had deployed Concentric's contracts. According to Concentric, the attacker posed as a recruiter on a professional networking site and got a team member to install malware disguised as a skills test, which exposed the wallet's private key.
With that key, the attacker took ownership of Concentric's contracts and replaced the vault code with a malicious version. This let them create vault shares out of thin air and cash them in, emptying the vaults of about 715 ETH, or roughly $1.7M. Soon after, Concentric warned that the attacker was also going after token approvals given to the vaults. The stolen funds were swapped to ETH and split across several wallets, one of which security firms linked to an earlier exploit of OKX's DEX. Concentric offered a $100k reward for information leading to the recovery of the funds.
The vault contracts still run the attacker's code, which lets the attacker take any tokens that wallets have approved to them. That means any approval you gave to a Concentric vault can still be used to empty the approved tokens from your wallet. If you ever used Concentric, revoke all approvals to its vault contracts on Arbitrum. Revoking protects what is still in your wallet, but it does not recover funds that were already taken.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →