FutureSwapX Suffers $395,000 Loss in Exploit on Arbitrum Network

BlockSec reports that a suspicious attack on FutureSwapX’s contract on Arbitrum exploited changePosition operations, leading to a $395,000 loss, with the cause still under investigation.

USDC
ARB

Summary

BlockSec reported that a suspicious attack on FutureSwapX, a DeFi platform on Arbitrum, led to a $395,000 loss. The attacker used multiple changePosition operations to manipulate the contract and withdrew USDC. The contract’s closed-source nature has complicated the investigation into the vulnerability, and BlockSec has yet to receive a response from the team.

Terms & Concepts
  • Arbitrum: A layer-2 scaling solution for Ethereum that improves transaction speed and lowers costs.
  • USDC (U.S. Dollar Coin): A stablecoin pegged to the U.S. dollar, widely used for digital transactions.
  • changePosition operation: A smart contract (self-executing blockchain code) function that adjusts a user's trading or liquidity position within a protocol.