User loses $1M due to approval bug on Ekubo Protocol, triggering warnings to revoke token permissions.
Security & Exploits ·
A user suffered a loss exceeding $1,000,000 equivalent to 17 BTC following an approval bug on Ekubo Protocol. The vulnerability affected multiple addresses across Ethereum and Arbitrum networks, including 0x8ccb1ffd5c2aa6bd926473425dea4c8c15de60fd and 0x4f168f17923435c999f5c8565acab52c2218edf2 on Ethereum, and 0xc93c4ad185ca48d66fefe80f906a67ef859fc47d on Arbitrum.
The incident has prompted urgent recommendations to revoke token approvals via services such as Revoke.cash to prevent further unauthorized fund access. According to reports, the drain transaction has been documented on blockchain explorers, and the matter has been escalated to relevant security contacts.
The exact mechanism of the approval bug and whether it represents a flaw in Ekubo's contract code or user error remains unclear. No statement from Ekubo Protocol addressing the issue has been provided, nor is the scope of exposure—whether this affects other users or remains isolated—yet established.