Ekubo Protocol approval bug results in $1M+ loss; users urged to revoke approvals immediately on Ethereum and Arbitrum.
Security & Exploits ·
A loss exceeding $1 million was traced to an approval vulnerability affecting Ekubo Protocol, according to a report on May 5, 2026. The incident involved approximately 17 BTC and impacted users across multiple networks. Three contract addresses were identified as vectors for the exploit: two on Ethereum (0x8ccb1ffd5c2aa6bd926473425dea4c8c15de60fd and 0x4f168f17923435c999f5c8565acab52c2218edf2) and one on Arbitrum (0xc93c4ad185ca48d66fefe80f906a67ef859fc47d).
Users holding active approvals to these addresses face ongoing risk. Immediate revocation of approvals is being recommended, with RevokeCash cited as a method for executing the transaction. The drain transaction has been documented on blockchain analysis tools for visibility into the movement of funds.
The vulnerability's underlying mechanics—whether rooted in smart contract logic, authorization design, or another technical flaw—remain unspecified in available reports. Whether additional losses or affected addresses may exist beyond those disclosed is also unclear.