T
iTokenly

Arcadia Finance hack — July 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 15, 2025
Target typeLending protocol
Loss$3,500,000Published estimates range $3,500,000 to $3,600,000Price at time of incident
MethodContract logic errorThe RebalancerSpot contract passed a user-supplied swapData parameter, including the address of the router that would perform the swap, through the call chain RebalancerSpot.rebalance() to AccountV1.flashAction() to actionTarget.executeAction() without validating it. CertiK observed that nowhere in that chain are the actionTarget and router addresses decoded from swapData examined; SolidityScan classified it under OWASP SC06:2025 Unchecked External Calls, resting on the assumption that the supplied router would always be a legitimate DEX. The attacker registered a contract they controlled as both the router and a whitelisted Arcadia account, obtaining arbitrary execution inside a privileged context and draining any account that had granted the Rebalancer asset-manager permissions.
ChainsBase, Ethereum
OutcomeUnresolved

What happened

Arcadia Finance, an on-chain margin protocol on Base, was drained on 15 July 2025 through its Rebalancer contract.

Arcadia let users delegate rebalancing of their margin accounts to an asset manager contract. The RebalancerSpot contract passed a user-supplied swapData parameter, including the address of the router that would execute the swap, straight through the call chain RebalancerSpot.rebalance() to AccountV1.flashAction() to actionTarget.executeAction() without validating it. CertiK noted that nowhere in that call chain are the actionTarget and router addresses decoded from swapData ever examined. SolidityScan classified the flaw under OWASP SC06:2025 Unchecked External Calls. By registering their own malicious contract as both the router and a whitelisted Arcadia account, the attacker spoofed a privileged execution context and pulled assets out of any account that had granted the Rebalancer asset-manager permissions, bypassing health checks by repaying debt first.

The figures were reported in stages and still differ. The Defiant and SolidityScan both give the loss as approximately $3.5 million, converted into roughly 840 ETH. CertiK's own write-up puts it at approximately $3.6 million, or 1,203 ETH swapped through 1inch. The two ETH figures are not reconcilable with a single USD total at July 2025 prices, and no party has published a reconciliation. Stolen USDC and USDS were swapped to wrapped ether on Base and the proceeds bridged to Ethereum mainnet.

Arcadia paused the affected contracts and told users to revoke all asset manager permissions. No public post-mortem was released. The stolen funds were not recovered and no arrests have been reported. Some users held third-party cover: Nexus Mutual, through the Base-based coverage seller OpenCover, paid roughly $250,000 in claims, with filing opening on 29 July after a 14-day cooldown — a small fraction of the loss.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. SolidityScanSecondary · retrieved 2026-08-01
  3. The DefiantSecondary · retrieved 2026-08-01
  4. Cointelegraph (via TradingView)Secondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Arcadia Finance hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/arcadia-finance
https://itokenly.com/hacks/arcadia-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.