Attackers drain $1.4M in wrapped bitcoin from DeFi protocol Ekubo in approval-based exploit
Quick Take
- DeFi protocol Ekubo reported losses of $1.4 million in wrapped bitcoin from its EVM swap router on May 5, but core liquidity providers and its Starknet deployment were unaffected.
- The exploit adds to more than $770 million in DeFi losses already recorded in 2026, following an April that saw roughly $620 million drained across nearly 30 separate exploits.
Ekubo Protocol lost roughly $1.4 million in wrapped bitcoin (WBTC) after attackers exploited an access control flaw in its EVM swap router contracts, adding another incident to an already difficult year for DeFi security.
Ekubo is a concentrated liquidity AMM originally built on Starknet that expanded to Ethereum and Arbitrum, known for its singleton architecture and modular extension system.
The attack targeted a vulnerable payment callback flaw within Ekubo's v2 EVM extension contracts, according to blockchain security firm Blockaid. The contracts accepted payer, token, and amount parameters from attacker-controlled payload data without verifying that the payer had authorized the transaction, Blockaid explained in a thread.
Attackers exploited the flaw to drain funds from wallets that had previously granted token approvals to the affected router contracts.
Bad actors notably executed the theft across approximately 85 rapid transactions.
The primary victim lost around 17 WBTC, with the stolen funds subsequently converted to WETH and DAI, according to onchain data flagged by security monitoring services, including Cyvers.
Ekubo moved quickly to alert users. "There is an active security incident on Ekubo's swap router contract on EVM chains only," the protocol wrote on X. "Liquidity providers are not affected.
The protocol's core Starknet deployment and its broader liquidity base were untouched, as confirmed by the Ethereum Layer 2 network's developer on X.
Ekubo’s team also urged all users to revoke outstanding approvals immediately via revoke.cash.
Crucially, Ekubo's EVM contracts are immutable by design, meaning a patched redeployment is the only path forward for the affected router. No further losses had been reported as of the time of publication.
2026 DeFi loses mount
The exploit on Ekubo is a textbook example of approval-based attack risk in modular DeFi architecture, a category of vulnerability that has resurfaced repeatedly across 2026's bruising stretch of protocol breaches.
DeFi losses for 2026 had already surpassed $750 million before the Ekubo incident, per The Block's prior coverage.
April alone saw roughly $620 million drained across nearly 30 separate incidents, one of the most hack-heavy months by incident count on record, according to The Block's exploits dashboard.
The Drift Protocol breach ($280 million) and the Kelp DAO exploit ($292 million) accounted for the bulk of that figure, though smaller incidents — including the $4.5 million Wasabi Protocol admin-key compromise and a $3.5 million Volo Protocol vault breach — kept the bleeding steady throughout the month.
Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.