Revoke.cash logo

Rubic Hack

Check if your address is affected.

25 Dec 2022
$1.51M stolen
Ethereum Logo

Rubic is a cross-chain DEX aggregator that finds swap routes across many exchanges and blockchains. Its contracts pass each swap on to one of a list of trusted routers, and users approve these contracts to spend their tokens. Rubic had added the USDC token contract itself to this trusted list, because some of its providers needed it. On 25 December 2022, an attacker realized that this let them route a fake swap through USDC and make Rubic transfer USDC from any wallet that had approved it.

About $1.5M in USDC was taken from users on Ethereum. The attacker swapped the stolen USDC for ETH and sent most of it to the Tornado Cash mixer to hide its trail. Rubic paused the affected contracts a little over an hour after the attack started, warned users not to use its website and asked everyone to revoke their approvals. Rubic then asked affected users to contact its support team and compensated them for their losses.

The affected contracts cannot be changed, so they were never repaired. They remain paused, and USDC is still on the trusted list of one of them, which means the exploit would work again if they were ever unpaused. Anyone who approved these contracts should revoke those approvals, even though the contracts are currently paused. Revoking protects what is still in your wallet, but it does not recover funds that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits