logo

Arcadia Incident Analysis

ID: 52ef8e6c-7063-5140-a44f-cc729aab63c5

STIX ID: report--52ef8e6c-7063-5140-a44f-cc729aab63c5

Feed Name: CertiK Blog

Threat Score
75/100

Date Published: 2025-07-15

Date Updated: 2026-06-11

...
...

On 15 July 2025, an attacker exploited insufficient input validation in Arcadia Finance’s Rebalancer/RebalanceSpot call chain by supplying arbitrary swapData that allowed reentrancy and execution of calldata targeting victim accounts; the attacker drained assets (~$3.6M worth of ETH) after repaying victim debt and withdrawing underlying tokens. The report includes step‑by‑step attack flow, key transaction links, attacker and contract addresses, fund flow (including bridging to Ethereum), and notes that Arcadia offered a 10% bounty for return of remaining funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.