CryptoReal
CASE FILE — Jan 13, 2025

Compromised Admin Key Lets Attacker Drain Moby Trade Vaults, Whitehats Save Most of the Rest

On January 8, a leaked private key allowed an attacker to take control of Moby Trade's vault contracts and withdraw just over $1 million in assets. A separate whitehat effort managed to intercept and rescue an additional $1.47 million in USDC before it could be drained through the same vulnerability.

01Discovery and initial response

Chaofan Shou was the first to publicly flag unusual on-chain activity affecting Moby Trade. In its initial statement, the protocol clarified that the incident did not stem from a flaw in its smart contract logic: "We want to emphasize that it was not a security issue related to the protocol's smart contracts — hackers attempted to steal funds by simply upgrading existing smart contracts using stolen proxy private keys."

02How the attack unfolded

Before targeting the mainnet contracts, the attacker tested the exploit path on Arbitrum Sepolia:

With a compromised admin key in hand, the attacker transferred contract ownership and proceeded to drain two vaults in sequence — first the S_VAULT, followed roughly thirty minutes later by the M_VAULT.

S_VAULT withdrawals:

Sums referenced in this case file

M_VAULT withdrawals:

03The whitehat rescue

The attacker's own upgrade path left an unprotected upgradeToAndCall function exposed. The SEAL911 team identified this and deployed a replacement implementation to secure $1.47 million in USDC that remained at risk. Tony Ke of SEAL911 described the intervention: "We just automatically hacked the hacker!"

Despite the successful rescue, SEAL911 trailed the original attacker by only about 30 seconds — not quite fast enough to prevent the WETH, WBTC, and USDC already withdrawn from being lost.

04Final tally

As of press time, the confirmed losses were:

  • 207.78 wETH: $627,678
  • 3.774 wBTC: $345,222
  • USDC: $30,180
  • Total stolen: $1,003,080
  • Amount rescued by SEAL911: $1,470,191

The stolen funds passed through more than 35 addresses before being bridged via Stargate to Ethereum, ending at address 0x6a92d4840309f447922114a349984a1d09a51470. The complete list of intermediary addresses is documented in Moby's detailed post-mortem.

05Aftermath

Moby Trade followed up with an incident report and later a full post-mortem. The protocol laid out its recovery plan: OLP depositors would be able to withdraw their deposits once systems were restored, funded by the team treasury, while options traders would either be compensated at "most favorable value" or have their positions returned intact. The team also acknowledged that its planned move to Berachain mainnet, announced separately, would be delayed.

Moby TradePrivate Key Leak
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.