← Radar

Incident case file

Sign in to watch

Aurellion Labs — Diamond Proxy Uninitialized Initializer Exploit

Incident date May 12, 2026

0 views

UnknownArbitrumDiamond proxy / Uninitialized contractCluster: AURELLION-ARB-2026-05

Estimated loss

$456K

Victims identified

3
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: 0x9f4...d5ca (partial — full address pending on-chain completion)

Funds moved to: TODO — ~$455K USDC drained; no public laundering trace yet
Attacker EOA partial: 0x9f4...d5ca (full address pending Arbiscan completion). Victim Diamond proxy partial: 0x0adc...f1b2. The attacker exploited the unprotected initialize(address) function on the SafeOwnable Facet of an EIP-2535 Diamond proxy. The _initialized storage slot was not properly updated, allowing re-initialization. After taking ownership, the attacker used diamondCut to inject a malicious facet containing pullERC20/sweep logic, draining $455,003 USDC from wallets that had pre-appro

Timeline: On May 12, 2026, an attacker exploited an uninitialized Diamond proxy contract belonging to Aurellion Labs, a tokenized real-world asset (RWA) protocol on Arbitrum. The vulnerability stemmed from an unprotected initialize(address) function on the SafeOwnable Facet of the EIP-2535 Diamond proxy, where the _initialized storage slot was not correctly set. The attacker called initialize() to take ownership, then used diamondCut to register a malicious facet implementing pullERC20 and sweep functions. The malicious facet drained ~$455,003 USDC from user wallets holding active approvals to the Diamond proxy. Blockaid and SlowMist flagged the exploit shortly after detection. Aurellion paused the affected project and committed to user reimbursement, issuing an advisory urging affected users to revoke any remaining approvals to the compromised proxy.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)