Incident case file
Sign in to watchAurellion Labs — Diamond Proxy Uninitialized Initializer Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x9f4...d5ca (partial — full address pending on-chain completion)
Timeline: On May 12, 2026, an attacker exploited an uninitialized Diamond proxy contract belonging to Aurellion Labs, a tokenized real-world asset (RWA) protocol on Arbitrum. The vulnerability stemmed from an unprotected initialize(address) function on the SafeOwnable Facet of the EIP-2535 Diamond proxy, where the _initialized storage slot was not correctly set. The attacker called initialize() to take ownership, then used diamondCut to register a malicious facet implementing pullERC20 and sweep functions. The malicious facet drained ~$455,003 USDC from user wallets holding active approvals to the Diamond proxy. Blockaid and SlowMist flagged the exploit shortly after detection. Aurellion paused the affected project and committed to user reimbursement, issuing an advisory urging affected users to revoke any remaining approvals to the compromised proxy.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/12/aurellion-labs-drained-of-455k-usdc-in-diamond-proxy-exploit/
- Articlecryptoadventure.comhttps://cryptoadventure.com/aurellion-labs-exploit-drains-456k-after-diamond-proxy-initialization-flaw/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)