Ekubo Hit Again: The Same Callback Flaw Silently Drained $1.4M Through Users' Old Approvals

Ekubosmart contractapproval attackBlockaidDeFi securityEthereumERC-20revoke approval

Same Vulnerability Class, Happening Again

According to monitoring by Blockaid, Ekubo Protocol's extension contract deployed on Ethereum was exploited again, with losses of approximately $1.4 million. The attack targeted Ekubo's V2 contract and affected users who had previously granted ERC-20 token approvals to the contract—native Ekubo users and liquidity providers were unaffected.

The technical pathway of this attack closely mirrors the earlier Ekubo incident on Starknet, with the root cause again pointing to missing identity verification in a contract callback function.

The Core Flaw: IPayer.pay Callback Did Not Verify Payer Identity

Specifically, the attacker exploited a design flaw in the contract's IPayer.pay callback function—this function failed to perform effective identity verification on the payer when executing payment logic.

The attacker designated user addresses holding valid ERC-20 approvals as payers, triggered the callback through the Core router, and called the transferFrom function to transfer victim assets without any active input from the user. The entire process was completely invisible to victims—until their assets were gone.

Once Granted, Approvals Carry Risk Indefinitely

This incident, together with the $5.87 million approval attack disclosed by CertiK on the same day, delivers a dual warning to the DeFi security space this week: once a contract approval is granted, the risk persists long after the original interaction ends.

Blockaid recommends that all users who have previously granted approvals to the Ekubo V2 contract immediately check and revoke relevant permissions using an approval management tool. For platform operators, establishing real-time monitoring of abnormal callback patterns and batch approval calls is now urgent. Trustformer KYT provides granular on-chain transaction behavior analysis, effectively identifying early signals of approval-abuse attacks and helping users and platforms compress the loss window to its shortest possible duration.

About Trustformer

Trustformer is a leading blockchain security and compliance technology company specializing in providing professional risk management and compliance solutions for the global cryptocurrency ecosystem. We have developed the cutting-edge Trustformer KYT (Know Your Transaction) platform, which integrates artificial intelligence, blockchain analytics, and regulatory technology to deliver comprehensive, accurate real-time transaction monitoring, risk assessment, and suspicious activity reporting services.

With deep industry expertise and technological innovation, Trustformer is dedicated to helping Virtual Asset Service Providers (VASPs), crypto financial institutions, and investors build a safer and more transparent crypto financial environment. We believe that driving compliance and trust through technology can contribute to the thriving growth of the global digital economy.