T
iTokenly

Moby hack — January 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 8, 2025
Target typeDecentralised exchange
Loss$2,500,000Price at time of incident
Recovered$1,470,192
MethodPrivate key compromiseA private key with proxy-admin rights over Moby's vault contracts was compromised. The attacker pushed unauthorised upgrades to the S_VAULT and M_VAULT proxies, reassigning admin and owner privileges to its own address, then called an emergency ERC-20 withdrawal function to drain the vaults.
ChainsArbitrum
OutcomeUsers reimbursed

What happened

Moby, an options protocol on Arbitrum, was drained on 8 January 2025 after an attacker obtained a private key with administrative rights over the protocol's proxy contracts. In its post-mortem Moby said the attacker identified and exploited a vulnerability in its key management system, without describing how the key was taken. The attacker pushed unauthorised upgrades to the S_VAULT and M_VAULT contracts, moving proxy admin and owner privileges to an address it controlled, then called an emergency withdrawal function to remove the assets.

Moby's own accounting lists 3.77 wBTC, 207.76 wETH and 1,500,371.68 USDC taken. Contemporaneous reporting by Protos and a review by Halborn both valued the total at about $2.5 million at the time; the post-mortem itself gives quantities rather than a dollar figure, so the USD total depends on the ETH and BTC prices used.

Much of it came back. While the attacker was attempting a further upgrade, the Seal 911 responder group — the work credited publicly to MEV researcher Tony Ke — noticed that the attacker's own replacement contract had left its upgrade function unprotected, used the same technique against it, and pulled 1,470,191.71 USDC back out of the M_VAULT contract. The wBTC and wETH had already been moved on; Ke said the rescue missed them by about thirty seconds, leaving roughly $1 million gone.

Moby said the incident was not a fault in its smart contract logic and committed to compensating all affected option holders and liquidity providers from treasury assets plus recovered funds, with payouts to holders of expired options by 13 January 2025.

Sources

  1. MobyPrimary · retrieved 2026-08-01
  2. ProtosSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01
  4. The Crypto TimesSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/moby-trade/moby-post-mortem-report-growth-plan-504ad5b0dd35

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Moby hack — January 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/moby
https://itokenly.com/hacks/moby

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.