Lumi Finance on Arbitrum hit by $270,000 exploit tied to ERC-4337 flaw

The attack exploited Sodium smart account validation logic, letting tokens be withdrawn from multiple user accounts without explicit approval while Lumi temporarily paused key vaults.

ARB
FLOW
CORE

Summary

Lumi Finance on Arbitrum was attacked on July 13, with losses of about $270,000, GoPlus said. The issue centered on the Sodium smart account contract’s ERC-4337 validateUserOp function, a key account-abstraction flow for handling user operations. In GoPlus’s account, the vulnerability emerged when _validateSignature called isValidSignatureNow and passed the signer parameter as the attacker’s address. That setup allowed the attack contract’s isValidSignature check to succeed after ECDSA.tryRecover failed without reverting, effectively bypassing the intended signature verification. The exploit reportedly let attackers withdraw tokens from multiple user-side accounts without explicit approval, while Lumi temporarily paused key vaults. The core liquidity pool was not targeted, according to The Crypto Times.

Terms & Concepts
  • ERC-4337: Account abstraction standard for smart accounts.
  • smart account: Programmable wallet controlled by contract logic.
  • ECDSA.tryRecover: Function used to recover a signer.