Gyroscope Incident Analysis
ID: 5cff35bb-2804-554b-a5b7-20cc9e7eb425
STIX ID: report--5cff35bb-2804-554b-a5b7-20cc9e7eb425
Feed Name: CertiK Blog
Threat Score
**Executive Summary:** On 30 January 2026 Gyroscope paused liquidity pools after an attacker exploited an arbitrary-input vulnerability in its cross-chain bridge (ccipReceive/BridgeToken) to grant themselves unlimited approval on the GYD token and withdraw ~6,099,337 GYD (~$807k); the attacker then deposited proceeds through Tornado Cash and Gyroscope offered a 33% white-hat bounty.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
