RISEx protocol suffered a $673k unauthorized withdrawal from a misconfigured vault but patched the issue and reimbursed all depositors from protocol fees.
Security & Exploits ·
A misconfiguration in RISEx's RWA strategy vault led to an unauthorized withdrawal of approximately 673,011.56 USDC on July 21 at 07:21 UTC. The protocol detected the issue within minutes, applied a patch by 08:09 UTC, and fully reimbursed affected XLP depositors using fees generated during July. The protocol stated this represented the only unauthorized withdrawal during the period and that depositors' funds remained unaffected overall.
The misconfiguration had existed since the RWA strategy's deployment on July 13, well before the withdrawal occurred. RISEx noted the incident was neither a novel attack nor caused by a dependency failure. Withdrawal throttles on the bridge, RISEx platform, and XLP vault are designed to limit exploit impact, though the withdrawn amount fell below those thresholds in this case.
The protocol has initiated engagement with SEAL 911 and tracing efforts, and is attempting to contact the address responsible for the withdrawal to request a return of funds. A postmortem review has been promised, and RISEx cautioned users against connecting wallets to any links claiming to offer recovery or claiming processes related to the incident.