Small team's arbitrage contract exploited via callback vulnerability on Hyperliquid, losing 5,000 USDC.
Security & Exploits ·
A small team lost 5,000 USDC through a callback vulnerability in their arbitrage contract on Hyperliquid, according to an onchain message posted to the exploited contract's address. The team stated the stolen amount represented their entire capital and that they were unable to identify the attacker.
The message, directed at the exploit actor, describes a flaw in the contract deployed at address 0xFE9D316F2E17c4C090038f161f4C38fca86b6Cea that allowed unauthorized fund withdrawal through a callback mechanism. Rather than pursue legal action, the team offered a 500 USDC bounty for the return of the funds to a specified wallet address, indicating a preference for amicable resolution.
No confirmation has emerged as to whether the exploit actor has responded to the bounty offer or returned any portion of the stolen funds. The nature of the callback vulnerability and how it was exploited remain undetailed in available disclosures.