IPOR Says Arbitrum Vault Lost $336K USDC, DAO to Fully Reimburse Depositors

IPOR Says Arbitrum Vault Lost $336K USDC, DAO to Fully Reimburse Depositors

N
News Editor 01
2026-07-23 20:40:16
IPOR said a malicious transaction drained $336,000 USDC from a legacy USDC Fusion Optimizer Vault on Arbitrum. The protocol said the loss was under 1% of Fusion funds, other vaults were unaffected, and the DAO treasury will fully reimburse impacted depositors.
IPORArbitrumUSDCsmart contract securityDAO reimbursement

IPOR said a malicious transaction drained $336,000 in USDC from its USDC Fusion Optimizer Vault on Arbitrum. The protocol said the affected amount represented less than 1% of Fusion’s total funds, that other vaults were not impacted, and that the IPOR DAO treasury will fully reimburse affected depositors.

Suspicious activity traced to a legacy vault

According to the project, the team was alerted to suspicious activity on January 6, 2026 and then confirmed that the attack had emptied a legacy vault on Arbitrum. IPOR described the incident as limited in scope because it hit an older deployment rather than the broader Fusion vault set. Still, the case exposed how inherited smart contract settings can open a path for loss.

IPOR said security firms Hexagate and Blockaid helped detect the incident early, while SEAL is assisting recovery efforts. The team also said it plans to publish a post-mortem covering the exploit, its root cause, and the mitigation steps taken after the breach.

Missing validation and delegated permissions were both involved

In IPOR’s description of the exploit path, the first weakness was in the vault’s instantWithdraw method, which lacked validation. That gap allowed unauthenticated fuse modules to execute arbitrary code. It was a narrow issue, but a serious one.

The second element involved an administrator account using EIP-7702 delegation to a contract that allowed arbitrary calls. IPOR said the attacker used that setup to make the vault treat the transaction as approved. With those permissions in hand, the attacker injected a malicious fuse and used the missing validation to withdraw assets, moving $336,000 USDC to the attacker’s address.

IPOR says newer Fusion vaults have stricter checks

The protocol said the exploited vault had been deployed about 490 days before stricter fuse validation policies were introduced. It added that the vulnerable EIP-7702 delegated contract was present only in a small number of older vaults. Newer Fusion Vaults, according to IPOR, include stronger validation that blocks the same attack pattern.

Its response now has two tracks: working with Hexagate, Blockaid, and SEAL to monitor and possibly recover the stolen funds, and covering the loss through the DAO treasury so depositors are made whole. Based on the details released so far, IPOR is framing the incident as a legacy-vault exploit rather than a platform-wide failure across Fusion.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.