T
iTokenly

Rubic hack — December 2022

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedDecember 25, 2022
Target typeDecentralised exchange
Loss$1,410,000Published estimates range $1,400,000 to $1,450,000Price at time of incident
MethodContract logic errorThe RubicProxy router's routerCallNative function did not validate the target address it was instructed to call, allowing arbitrary external calls through the proxy. Combined with USDC having been added to the router whitelist, this let the attacker make the proxy execute transferFrom against every wallet holding an open approval to it.
ChainsEthereum
OutcomeUsers reimbursed

What happened

On 25 December 2022 an attacker drained about $1.41 million from users of Rubic, a cross-chain swap aggregator, on Ethereum. The flaw was in the RubicProxy router: the routerCallNative function did not validate the address it was told to call, so an attacker could point it at a contract of their own and have the proxy execute arbitrary instructions. Because Rubic had also mistakenly added USDC to the router's supported list, those instructions could include transferFrom calls against every wallet that had granted the proxy a token approval, so the losses fell on users rather than on protocol-held funds. PeckShield flagged the incident and traced the attacker's contract. QuillAudits' transaction analysis put the proceeds at roughly 1,188 ETH, sent on to Tornado Cash. Rubic paused its contracts within hours, delisted USDC and told users to revoke approvals immediately. In its own weekly report the team described the cause as a USDC address whitelisted for interaction with its contracts so that a partner's bridge could operate via other aggregators, said the contract became compromised as a result, and committed the founders' personal savings to repaying affected users: up to $5,000 each in the first tranche and a further $5,000 by the end of January 2023, which it expected to cover 76 per cent of victims, with 16 per cent supported over six to nine months and 8 per cent on individual plans. Rubic published no loss total of its own; the $1.4 to $1.45 million range comes from PeckShield's on-chain estimate as relayed by reporting at the time. This was Rubic's second incident of 2022, following a separate admin-wallet key compromise on 2 November that cost over $1.2 million.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x253dD81d642220267ccAc1d8202c0B96a92b299e

Sources

  1. RubicPrimary · retrieved 2026-08-01
  2. crypto.newsSecondary · retrieved 2026-08-01
  3. QuillAuditsSecondary · retrieved 2026-08-01
  4. CoinDeskSecondary · retrieved 2026-08-01

Official post-mortem: https://cryptorubic.medium.com/rubic-weekly-report-12-29-2022-4f10d21720e6

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Rubic hack — December 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/rubic
https://itokenly.com/hacks/rubic

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.