지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Inflated Books: The $250K Attack on Sperax USD

보고서 ·사고 분석 ·
Inflated Books: The $250K Attack on Sperax USD

Project name: Sperax USD/Sperax

Project type: Token

Date of exploit: Feb 4, 2023

Asset loss: $250k

Vulnerability: Incorrect Logic in Migration/Rebasing Mechanism

Date of audit report publishing:

  • Dec 22, 2021: Sperax VI
  • Oct 26, 2021: Sperax

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Sperax USD is a DeFi project providing services including USDs (liquid-staked stablecoin) and Demeter (multi-DEX liquidity management protocol) on Arbitrum. The USDs contract was exploited by a potential vulnerability in the accounting migration mechanism. The attacker utilized this vulnerability to inflate the supply of USDs.

Nature of the Vulnerability

  • Since the contract was unverified, we can only know the USDs updated the balance of the account incorrectly.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.53.23 AM

Conclusion

On Feb 4, 2023, SperaxUSD was attacked, leading to a loss of $250K due to the incorrect logic in its Migration/Rebasing Mechanism.

The compromised contract is Sperax's stablecoin contract (Sperax USD, USDs), which is out of CertiK's audit scope (staking and SperaxToken contracts).

References

SperaxUSD’s announcement:

관련 블로그

Gyroscope Incident Analysis

Gyroscope Incident Analysis

On 30 January 2026, Gyroscope announced via their X account that they had paused liquidity pools due to an issue with their cross-chain contract. The issue led to losses of 6M Gyro Dollar (GYD) tokens with approximately $807k of liquidity extracted by the attacker.

Numa Incident Analysis

Numa Incident Analysis

On 10 August 2025 Numa protocol was exploited for ~$313k. A malicious actor acquired additional Numa tokens by liquidating victim accounts after manipulating the NumaVault by minting nuBTC. Minting the nuBTC inflated the total synth value and in turn, reduced the collateral value of cNuma according to the Numa VaultManager logic.

Clober Dex Incident Analysis

Clober Dex Incident Analysis

On 10 December 2024, Clober DEX liquidity vault on Base Network was exploited resulting in a loss of 133.7 ETH (~$501k). The root cause of the attack was a reentrancy vulnerability in the _burn() function of the Rebalancer contract. Clober made an announcement via their X account, offering a 20% bounty to the attacker.