Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Arcadia Finance Hack Steals $3.5M in WETH

July 21, 2025
Reading Time: 2 mins read
in Incidents
Arcadia Finance Hack Steals $3.5M in WETH

Arcadia Finance, a decentralized finance (DeFi) platform operating on the Base blockchain, recently experienced a significant exploit, resulting in the theft of approximately $3.5 million in cryptocurrency. The attack specifically targeted a vulnerability within Arcadia’s Rebalancer contract. This flaw allowed the attacker to manipulate swapData parameters, leading to unauthorized swaps that drained assets from user vaults.

The exploit unfolded swiftly, with the attacker deploying a malicious contract and triggering the vulnerability within a minute.

According to blockchain security company Cyvers, the initial attack occurred on Tuesday. The stolen tokens, primarily USDC and USDS, were immediately swapped for Wrapped Ethereum (WETH) on the Base network. To further obscure the trail, these WETH holdings were then bridged over to the Ethereum mainnet, where they were distributed across new intermediary addresses, likely in an attempt to prevent tracking and potentially for mixing or decentralized exchange activity.

Initially, the loss was estimated at $2.5 million, comprising around 2.3 million USDC and 227,000 USDS. During the rogue swap process, the attacker gained approximately 199 WETH and 965.8 million AERO tokens, impacting 12 different addresses. However, Cyvers later confirmed that Arcadia Finance suffered a subsequent attack, with the exploiter successfully extracting an additional nearly $1 million through multiple transactions, bringing the total stolen amount to $3.5 million.

In response to the incident, Cyvers provided several recommendations to mitigate further damage and assist in recovery.

These included blacklisting the involved addresses on both the Base and Ethereum networks, notifying major exchanges and bridges to halt any inbound transactions from these addresses, and sharing suspicious activity reports with law enforcement agencies. These measures are crucial for limiting the attacker’s ability to cash out the stolen funds.

The Arcadia Finance team officially confirmed the exploit on Tuesday via a post on X. They acknowledged the “unauthorized transactions via a Rebalancer” and urgently advised their users to revoke all permissions granted to asset managers within the Arcadia platform to minimize any further potential risks. They also stated that more information would be provided as their investigation progressed.

Reference:

  • Arcadia Finance Exploited in $3.5M Hack with Funds Quickly Laundered and Converted to WETH
Tags: cyber incidentsCyber Incidents 2025Cyber threatsJuly 2025
ADVERTISEMENT

Related Posts

Sitecore Exploit Chain Warning

Lotte Card Cyberattack Reported

September 2, 2025
Sitecore Exploit Chain Warning

Zscaler Data Breach Exposes Info

September 2, 2025
Sitecore Exploit Chain Warning

Von Der Leyen Plane GPS Jamming

September 2, 2025
MathWorks Confirms Cyberattack Data Stolen

MathWorks Confirms Cyberattack Data Stolen

September 1, 2025
MathWorks Confirms Cyberattack Data Stolen

Fraudster Stole Millions From Baltimore

September 1, 2025
MathWorks Confirms Cyberattack Data Stolen

Google Warns Salesloft Breach Hit Accounts

September 1, 2025

Latest Alerts

High Risk SQLi In WordPress Plugin

AI Weaponized Nx Supply Chain Attack

Sitecore Exploit Chain Warning

Brokewell Android Malware In Fake Ads

North Korea APT37 Uses RokRAT In Phishing

New Zero Click Exploit Targets WhatsApp

Subscribe to our newsletter

    Latest Incidents

    Lotte Card Cyberattack Reported

    Von Der Leyen Plane GPS Jamming

    Zscaler Data Breach Exposes Info

    Google Warns Salesloft Breach Hit Accounts

    Fraudster Stole Millions From Baltimore

    MathWorks Confirms Cyberattack Data Stolen

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial