A recent exploit on Ekubo Protocol has resulted in the loss of approximately $1.4 million, primarily in Wrapped Bitcoin (WBTC). The attacker targeted the platform's swap router contracts on Ethereum and Arbitrum, exploiting a "missing payer validation" flaw in the code. This allowed them to drain funds from wallets that had previously granted unlimited approvals to those contracts.
Attack Details: Missing Validation in Swap Routers
The exploit executed 85 rapid transactions, siphoning roughly 17 WBTC (~$81,170 on-chain value). The vulnerability only affected users who had approved specific router addresses on Ethereum and Arbitrum. Liquidity providers (LPs) and users on the Starknet network remain unaffected. The core AMM contracts and the Starknet DEX continue to operate normally.
Affected Addresses and Steps to Secure Funds
If you have interacted with Ekubo's swap on Ethereum or Arbitrum, check your wallet permissions immediately. The team recommends visiting revoke.cash to cancel approvals for the following addresses: V2 router: 0x8ccb1ffd5c2aa6bd926473425dea4c8c15de60fd; V3 routers: 0x4f168f17923435c999f5c8565acab52c2218edf2 and 0xc93c4ad185ca48d66fefe80f906a67ef859fc47d. Revoking these permissions prevents the attacker from moving additional funds.
Current Status and Warnings
The Ekubo team is preparing a post-mortem report but has not yet announced any compensation plan for affected users. Beware of phishing scams offering fake refund links. This incident serves as a stark reminder: always revoke token approvals after completing swaps to avoid similar losses.

