T
iTokenly

WUSD.fi (GLOVE rewards) hack — May 2026

Verified — 3 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedMay 25, 2026
Target typeStablecoin or yield protocol
Loss$200,000Price at time of incident
MethodContract logic errorWrapping WUSD minted up to 2 GLOVE to any address holding fewer than 2, with no protection against one person using many addresses, so the attacker farmed GLOVE from fresh addresses and sold it into the GLO pools
ChainsEthereum
OutcomeUnresolved

What happened

WUSD.fi, a wrapped-dollar token on Ethereum that rewards wrapping with a token called GLOVE, was exploited on 25 May 2026, losing about $200,000 of USDC and USDT from the Uniswap V3 pools that paired GLOVE with stablecoins, according to ExVul's alert that morning.

According to ExVul and a DeFiHackLabs reconstruction, the wrap function minted up to 2 GLOVE to any address that wrapped at least 100 WUSD while holding fewer than 2 GLOVE, with nothing to stop one person using many addresses. Using EIP-7702 helper contracts and a USDT flash loan from Morpho, the attacker repeated wrap-and-unwrap cycles from fresh addresses, harvested GLOVE and sold it into the GLO pools.

This registry read one of the attack transactions, at 06:07:59 UTC, in which the pools paid 11,702.08 USDC and 8,079.16 USDT to the attacker's address. The campaign total was not summed on-chain here, so ExVul's estimate of about $200,000, which DeFiHackLabs also uses, is recorded. No statement from the project or recovery has been found.

Sources

  1. ExVul on XSecondary · retrieved 2026-10-06
  2. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  3. Ethereum transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Changes to this entry

  • Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "WUSD.fi (GLOVE rewards) hack — May 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/wusd-fi-glove-may-2026
https://itokenly.com/hacks/wusd-fi-glove-may-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.