Moby Trade Hack
Check if your address is affected.
Moby Trade is a decentralized options trading platform on Arbitrum. On 8 January 2025, an attacker gained control of the private key that Moby used to authorize upgrades to its core contracts. According to Moby, the key had far more power than it needed, and the attacker found a weakness in how it was protected. With that key, the attacker replaced several of Moby's contracts with malicious versions and made themselves the owner. This gave them access to the funds in Moby's liquidity pools and to tokens in the wallets of users who had approved these contracts.
The attacker drained about $2.55M from the liquidity pools and a further $863k directly from users' wallets through their active approvals. While the attacker was attempting another upgrade, a whitehat working with the SEAL911 security team used a gap to rescue about $1.47M of USDC from the pools, leaving a net loss of about $1.9M. The rest was swapped to ETH, moved to Ethereum and spread across many wallets. Moby offered the attacker a bounty through on-chain messages but got no response.
Moby promised to compensate affected options and liquidity positions from its treasury. For funds drained through approvals, it only said the cases were being investigated with security partners. The compromised contracts are still controlled by the attacker, so any remaining approval to them can still be used to take tokens from your wallet. If you ever used Moby Trade on Arbitrum, check your wallet and revoke any approvals that remain for its contracts.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →