Incident case

Rubic 2022 RubicProxy approval exploit

A RubicProxy routing flaw allowed arbitrary calls through a whitelisted USDC address and exposed user allowances. Security reports placed the stolen user funds around USD 1.4–1.5 million, after which affected contracts were stopped and later replaced with rewritten and audited contracts.

reviewedcurrent

Incident facts

Incident title
Rubic 2022 RubicProxy approval exploit
Bridge
Rubic
Incident date
2022-12-25
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDC, WETH, ETH
Attack category
Smart Contract Bug
Reported loss
Approximately USD 1.4–1.5 million
Recovery
None
Reimbursement
Unknown
Restart
Replaced
Current outcome
Active After Incident
Resolution
Unresolved
Last reviewed
2026-07-28
Last verified
2026-07-28

Timeline events

  • RubicProxy approval exploit occurred2022-12-25

    An attacker abused RubicProxy routing validation and approved user allowances to transfer USDC and convert it to ETH.

    Exploit OccurredHigh
  • Rubic stopped affected contracts and warned users2022-12-25

    Rubic stopped affected contracts and advised users to revoke approvals while the exploit was investigated.

    Transfers SuspendedHigh
  • Rewritten Rubic contracts entered production2023-04

    Later first-party contract documentation stated that rewritten and audited Rubic contracts launched in April 2023.

    Bridge ReopenedHigh
  • Rubic published updated security architecture2024-02-16

    Rubic described rewritten contracts, audits, multisignature management, server hardening, monitoring, a CISO function, and a planned bug bounty.

    Audit PublishedHigh

Evidence records

Known unknowns