Inflated Books: The $250K Attack on Sperax USD

Research Incident Analysis
Inflated Books: The $250K Attack on Sperax USD

Project name: Sperax USD/Sperax

Project type: Token

Date of exploit: Feb 4, 2023

Asset loss: $250k

Vulnerability: Incorrect Logic in Migration/Rebasing Mechanism

Date of audit report publishing:

  • Dec 22, 2021: Sperax VI
  • Oct 26, 2021: Sperax

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Sperax USD is a DeFi project providing services including USDs (liquid-staked stablecoin) and Demeter (multi-DEX liquidity management protocol) on Arbitrum. The USDs contract was exploited by a potential vulnerability in the accounting migration mechanism. The attacker utilized this vulnerability to inflate the supply of USDs.

Nature of the Vulnerability

  • Since the contract was unverified, we can only know the USDs updated the balance of the account incorrectly.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.53.23 AM

Conclusion

On Feb 4, 2023, SperaxUSD was attacked, leading to a loss of $250K due to the incorrect logic in its Migration/Rebasing Mechanism.

The compromised contract is Sperax's stablecoin contract (Sperax USD, USDs), which is out of CertiK's audit scope (staking and SperaxToken contracts).

References

SperaxUSD’s announcement:

Related Blogs

Fortress Loans Incident Analysis

Fortress Loans Incident Analysis

An attacker was able to manipulate the project’s oracle allowing them to borrow a number of different tokens with inflated collateral and swap them leading to a drain of ~$3M (1,048.1 ETH and 400,000 DAI).

Numa Incident Analysis

Numa Incident Analysis

On 10 August 2025 Numa protocol was exploited for ~$313k. A malicious actor acquired additional Numa tokens by liquidating victim accounts after manipulating the NumaVault by minting nuBTC. Minting the nuBTC inflated the total synth value and in turn, reduced the collateral value of cNuma according to the Numa VaultManager logic.

GMX Incident Analysis

GMX Incident Analysis

On 9 July 2025 GMX V1 vault was exploited by a white-hat for ~$42M due to a reentrancy issue. The funds were later returned to GMX who awarded the white-hat a 10% bounty. The whitehat had minted and then staked GLP before creating a short position directly from the vault contract through reentrancy. Executing in this order bypassed the ShortsTracker, and prevented the average short position price from being updated. This occurs when the market price exceeds the tracked average price, resulting in the protocol overestimating unrealized losses. As a result, the Assets Under Management (AUM) calculation was manipulated to inflate the apparent value of GLP.