Incident case

Rubic 2022 RubicProxy approval exploit

A RubicProxy routing flaw allowed arbitrary calls through a whitelisted USDC address and exposed user allowances. Security reports placed the stolen user funds around USD 1.4–1.5 million, after which affected contracts were stopped and later replaced with rewritten and audited contracts.

reviewedcurrent

Incident facts

Incident title
Rubic 2022 RubicProxy approval exploit
Bridge
Rubic
Incident date
2022-12-25
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDC, WETH, ETH
Attack category
Smart Contract Bug
Reported loss
Approximately USD 1.4–1.5 million
Amount confidence
Medium
Loss amount basis
Mixed Sources
Recovery
None
Reimbursement
Unknown
Restart
Replaced
Current outcome
Active After Incident
Postmortem
Unclear
Resolution
Unresolved
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

Independent technical reports generally place stolen approved-user USDC around USD 1.4–1.5 million before conversion to approximately 1,188 ETH.

The canonical range excludes an erroneous USD 14.47 million rendering in one article describing approximately 1,188 ETH.

Why this remains unresolved

Timeline events

  • RubicProxy approval exploit occurred2022-12-25

    An attacker abused RubicProxy routing validation and approved user allowances to transfer USDC and convert it to ETH.

    Exploit OccurredHigh
  • Rubic stopped affected contracts and warned users2022-12-25

    Rubic stopped affected contracts and advised users to revoke approvals while the exploit was investigated.

    Transfers SuspendedHigh
  • Rewritten Rubic contracts entered production2023-04

    Later first-party contract documentation stated that rewritten and audited Rubic contracts launched in April 2023.

    Bridge ReopenedHigh
  • Rubic published updated security architecture2024-02-16

    Rubic described rewritten contracts, audits, multisignature management, server hardening, monitoring, a CISO function, and a planned bug bounty.

    Audit PublishedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.