Compromised Admin Key Lets Attacker Drain Moby Trade Vaults, Whitehats Save Most of the Rest
On January 8, a leaked private key allowed an attacker to take control of Moby Trade's vault contracts and withdraw just over $1 million in assets. A separate whitehat effort managed to intercept and rescue an additional $1.47 million in USDC before it could be drained through the same vulnerability.
01Discovery and initial response

Chaofan Shou was the first to publicly flag unusual on-chain activity affecting Moby Trade. In its initial statement, the protocol clarified that the incident did not stem from a flaw in its smart contract logic: "We want to emphasize that it was not a security issue related to the protocol's smart contracts — hackers attempted to steal funds by simply upgrading existing smart contracts using stolen proxy private keys."
02How the attack unfolded
Before targeting the mainnet contracts, the attacker tested the exploit path on Arbitrum Sepolia:
- Attacker address (testnet): 0x2a566D111d0a5Be888FEC5F3834434Af3245Bb1b
With a compromised admin key in hand, the attacker transferred contract ownership and proceeded to drain two vaults in sequence — first the S_VAULT, followed roughly thirty minutes later by the M_VAULT.
- Attacker address (mainnet): 0x2a566D111d0a5Be888FEC5F3834434Af3245Bb1b
- Ownership transfer transaction: 0x9da34da770f1e9c5d5e176578b32710d8e288587d8401582f34a9631edf9be4b
S_VAULT withdrawals:
- 30,180 USDC — transaction
- 0.074 wBTC ($6,776) — transaction
- 0.786 wETH ($2,376) — transaction
M_VAULT withdrawals:
- 206.97 ETH ($625,302) — transaction
- 3.70 wBTC ($338,446) — transaction
03The whitehat rescue
The attacker's own upgrade path left an unprotected upgradeToAndCall function exposed. The SEAL911 team identified this and deployed a replacement implementation to secure $1.47 million in USDC that remained at risk. Tony Ke of SEAL911 described the intervention: "We just automatically hacked the hacker!"
- $1.47M USDC rescue transaction: 0xa247fb0c2a641ad09f3c798c754662ee46ec56ebebc85c17afa397fdeaafe64a
Despite the successful rescue, SEAL911 trailed the original attacker by only about 30 seconds — not quite fast enough to prevent the WETH, WBTC, and USDC already withdrawn from being lost.
04Final tally

As of press time, the confirmed losses were:
- 207.78 wETH: $627,678
- 3.774 wBTC: $345,222
- USDC: $30,180
- Total stolen: $1,003,080
- Amount rescued by SEAL911: $1,470,191
The stolen funds passed through more than 35 addresses before being bridged via Stargate to Ethereum, ending at address 0x6a92d4840309f447922114a349984a1d09a51470. The complete list of intermediary addresses is documented in Moby's detailed post-mortem.
05Aftermath
Moby Trade followed up with an incident report and later a full post-mortem. The protocol laid out its recovery plan: OLP depositors would be able to withdraw their deposits once systems were restored, funded by the team treasury, while options traders would either be compensated at "most favorable value" or have their positions returned intact. The team also acknowledged that its planned move to Berachain mainnet, announced separately, would be delayed.
Get new scam files the moment we publish them — usually 2–3 emails a week.