← Radar

Incident case file

Sign in to watch

Lumi Finance — ERC-4337 UserOp Validation Side-Effect Drain (Sodium Smart Accounts)

Incident date July 13, 2026

2 views

ActiveArbitrum OneAccount abstraction / ERC-4337 paymaster abuseCluster: LUM-AA-2026-07

Estimated loss

$270K

Victims identified

50
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Attacker EOA: 0xCe1a3BB0b98D0D90C7Dd0620Ab86C9A771888d88 (funded from FixedFloat 2 no-KYC exchange ~4 days before the attack — methodical preparation pattern). Malicious sweeper contract: 0x56362412AE17cac443AAFBAb4289946Ad958E8a1.

Funds moved to: Primary exploit tx 0x020995ec0b5daafe8fab481e33b1b52fdbd6423578060a1f73fd2a9b9fb0ea90 (Arbitrum block 483390715, 160 logs, 117 ERC-20 transfers). In one atomic transaction: sweeper consolidates LUA + LUAUSD + USD₮0 + USDC + USDC.e from 50+ Sodium smart accounts, then executes swaps: 3,571 USD₮0 → 2.002 WETH via 0x641C00A8...074E5c79d; USDC → WETH via Uniswap V3 Pool; USDC.e → WETH via 0xC31E54c7...1c41fa443. Payout to attacker EOA: 2.00243 WETH (~$3,681) + 2,731.63 LUA (~$8,522) + 3,27
Attacker EOA 0xCe1a3BB0b98D0D90C7Dd0620Ab86C9A771888d88 (funded 4 days pre-attack via FixedFloat 2). Malicious sweeper contract 0x56362412AE17cac443AAFBAb4289946Ad958E8a1. ERC-4337 Entry Point 0.6.0 at 0x5FF137D4b0FDCD49DcA30c7CF57E578a026d2789 (older EntryPoint version — Cascade attack same week used 0.7.0). 50+ affected Sodium smart accounts visible in the exploit tx (e.g. 0x6990Ac28..., 0x4FBe80A9..., 0x7F110736..., 0x9be8286e..., 0xC3178b41..., 0xE9F616d0..., 0xcD68D8AA..., etc.). Cash-out

Timeline: ~4 days pre-attack: attacker EOA 0xCe1a3BB0... funded from FixedFloat 2 (no-KYC exchange) in methodical preparation pattern comparable to Cascade rehearsals. July 13, 2026 ~13:53 UTC: primary exploit tx 0x020995ec... executed at block 483390715 on Arbitrum. In one atomic transaction, the attacker exploits Sodium smart accounts by controlling a malicious paymaster that obtains ERC-20 allowances from 50+ smart accounts through validation-time side effects (a violation of ERC-4337 spec that requires strict separation between validation and execution). The paymaster silently gets approvals during validateUserOp() without any explicit user signature or key compromise. The sweeper contract 0x56362412... batch-drains LUA, LUAUSD, USD₮0, USDC, USDC.e from the compromised accounts, then swaps stables to WETH within the same tx. Blockaid detects and posts the alert (tweet 2076621100872614069, 13:53 UTC). Follow-up tweet 2076621683817873639 (13:55 UTC) publishes the attacker address and tx hash. SlowMist TI Alert relays the alert with a slightly different USD figure (~$264K). Post-exploit (July 13-17): attacker laundering path — Approve + Withdraw WETH to ETH, 6 consecutive 1 ETH deposits + smaller amounts to 0x0D5550d5... (typical mixer/bridge deposit pattern), KyberSwap Meta Aggregation Router v2 used to resell LUA/LUAUSD tokens over the following days, ETH deposits to 0x10D8b8Da... Final EOA balance ~0.0288 ETH by July 17 — attacker offloaded nearly everything within 4 days. No official post-mortem or compensation plan from Lumi Finance as of report date.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)