defirisk.co
rubric v1.7.0

Moby Trade: Private key compromise → proxy admin key stolen → vault ownership transfer → drain

Moby Trade lost roughly $1M when stolen proxy admin private keys were used to upgrade and drain two vaults — though a whitehat crew rescued $1.47M USDC before the attacker could reach it.

Occurred 2025-01-08 Loss $1M Status closed

Summary #

Moby Trade suffered a Perpetuals DEX on 2025-01-08, resulting in a loss of approximately $1M.

What happened #

Moby Trade lost roughly $1M when stolen proxy admin private keys were used to upgrade and drain two vaults — though a whitehat crew rescued $1.47M USDC before the attacker could reach it.

Linked factors #

  • RD-F-007 — related : Bug bounty absent — baseline integrity gap [via dashboard_risk_factors/Bug bounty: Unknown]
  • RD-F-101 — illustrative : Large governance proposal queued — RT signal would have fired [via realtime_signals/Governance/admin action: Y — proxy ownership transfer was the triggering on-chain event; detectable before drain began]