Ekubo Protocol Loses $1.4M wBTC to Access Control Exploit in EVM Router
Ekubo Protocol disclosed a $1.4 million (17 WBTC) loss from an access control flaw in its v2 EVM swap router, exploited on May 5 via unchecked callbacks and token.transferFrom abuse. Attackers drained funds through 85 rapid transactions, converting proceeds to WETH and DAI for obfuscation. Core Starknet operations and liquidity providers remain unaffected, but immutable EVM contracts demand redeployment. Initial reports surfaced at 08:00 UTC on May 6, with escalating details on approval risks by 13:12 UTC, amid 2026 DeFi hacks exceeding $750 million.