Rubic 2022 RubicProxy approval exploit
A RubicProxy routing flaw allowed arbitrary calls through a whitelisted USDC address and exposed user allowances. Security reports placed the stolen user funds around USD 1.4–1.5 million, after which affected contracts were stopped and later replaced with rewritten and audited contracts.
Incident facts
- Incident title
- Rubic 2022 RubicProxy approval exploit
- Bridge
- Rubic
- Incident date
- 2022-12-25
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum
- Affected assets
- USDC, WETH, ETH
- Attack category
- Smart Contract Bug
- Reported loss
- Approximately USD 1.4–1.5 million
- Amount confidence
- Medium
- Loss amount basis
- Mixed Sources
- Recovery
- None
- Reimbursement
- Unknown
- Restart
- Replaced
- Current outcome
- Active After Incident
- Postmortem
- Unclear
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Independent technical reports generally place stolen approved-user USDC around USD 1.4–1.5 million before conversion to approximately 1,188 ETH.
The canonical range excludes an erroneous USD 14.47 million rendering in one article describing approximately 1,188 ETH.
approved-user USDC transferred and converted to approximately 1,188 ETHapproximately USD 1.45 million
Used as the midpoint display amount.
Why this remains unresolved
- Reviewed sources do not establish attacker return or protocol recovery.
- Reviewed sources do not establish completed reimbursement for every affected wallet.
Timeline events
RubicProxy approval exploit occurred2022-12-25
An attacker abused RubicProxy routing validation and approved user allowances to transfer USDC and convert it to ETH.
Rubic stopped affected contracts and warned users2022-12-25
Rubic stopped affected contracts and advised users to revoke approvals while the exploit was investigated.
Rewritten Rubic contracts entered production2023-04
Later first-party contract documentation stated that rewritten and audited Rubic contracts launched in April 2023.
Rubic published updated security architecture2024-02-16
Rubic described rewritten contracts, audits, multisignature management, server hardening, monitoring, a CISO function, and a planned bug bounty.
Evidence records
- Rubic incident announcementRubic · Tier 1 · High reliability · primary · 2022-12-25Claim scope: Incident Case
Official incident notice referenced by multiple technical analyses.
- Decoding Rubic Exchange ExploitQuillAudits · Tier 2 · High reliability · secondary · 2022-12-27Claim scope: Incident Case
Technical analysis of RubicProxy arbitrary-call and approved-USDC loss.
- Dcentralab Diligence Analysis: Rubic DEX Aggregator HackDcentralab Diligence · Tier 2 · High reliability · secondary · 2022-12-26Claim scope: Incident Case
Independent root-cause and user-approval analysis.
- How Was Rubic Protocol Hacked?Neptune Mutual · Tier 2 · High reliability · secondary · 2023-01-02Claim scope: Incident Case
Independent technical and amount confirmation.
- Rubic’s New Security ArchitectureRubic · Tier 1 · High reliability · primary · 2024-02-16Claim scope: Restart
First-party security architecture, rewritten contracts, audits, management controls, and monitoring context.
- How to Swap Using Rubic’s ContractsRubic · Tier 1 · High reliability · primary · 2023-12-07Claim scope: Restart
States that new audited contracts launched in April 2023 and supports current active operation.
- Rubic incident announcementRubic · Tier 1 · High reliability · primary · 2022-12-25Claim scope: Incident Case
Event-scoped primary copy supporting the RubicProxy approval exploit, approximate amount, affected approval path, and containment response.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final user-by-user restitution outcome is not established.
- The exact transition date from stopped affected contracts to all rewritten production contracts is recorded only at month precision.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.