Tools Crypto Exploit Tracker exploit-0047
Exploit record
Ekubo
- Loss
- $1M
- Attack vector
- Smart Contract Bug
- Chain
- Ethereum
- Sector
- DEX
What happened
On 6 May 2026 attackers drained about $1.4 million, mostly in wrapped bitcoin, from users of Ekubo's EVM swap router contracts via an approval-based exploit.
The router's IPayer.pay callback failed to verify that the payer matched the lock initiator, so attackers could craft a malicious lock payload naming any address as payer and call transferFrom against wallets that had approved the routers, looping the exploit roughly 85 times at about 0.2 WBTC per iteration. Only the Ethereum V2/V3 and Arbitrum V3 routers were affected; Starknet's core deployment and all liquidity providers were untouched, and Ekubo urged users to revoke approvals on the three affected immutable contracts.
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
