Ekubo Protocol lost $1.4 million in wrapped bitcoin through an approval-based exploit targeting its v2 contract. Attackers abused a flaw in the IPayer.pay callback that allowed control over payer, token, and amount details, draining tokens users had approved for the v2 contract as a spender. Core protocol users were unaffected. The attack adds to $6.1 billion in DeFi exploit losses tracked by ChainSec through April 30, 2026.
Ekubo Protocol exploit
- ▪Ekubo Protocol suffered a $1.4 million wrapped bitcoin drain through an approval-based exploit
- ▪Ekubo Protocol's core protocol users were not impacted by the exploit
- ▪The main risk from the Ekubo Protocol exploit applies to users who approved the v2 contract as a token spender
- ▪The Ekubo Protocol exploit targeted the v2 contract
Approval-based attack mechanism
- ▪The Ekubo Protocol attacker abused a flaw in the IPayer.pay callback
- ▪The Ekubo Protocol attacker transferred tokens that users had already approved for the v2 contract
- ▪The Ekubo Protocol attack targeted user token approvals rather than Ekubo's core liquidity
- ▪The IPayer.pay callback flaw allowed the Ekubo Protocol attacker to control key details such as the payer, token, and amount
Token approval risks in DeFi
- ▪Wrapped bitcoin brings Bitcoin liquidity into DeFi
- ▪ChainSec's tracker listed 191 DeFi exploit cases by April 30, 2026
- ▪ChainSec's tracker reported DeFi exploit losses above $6.1 billion by April 30, 2026
User security recommendations
- ▪Ekubo Protocol users should review wallet permissions and revoke any unnecessary approvals linked to Ekubo's v2 contract
- ▪Callback design, spender permissions, and connected contract logic can become weak points in DeFi protocols
Story comments
Loading comments…