Multisig hack timeline

UPCX2025-04 $70M

Leaked admin key led to a malicious ProxyAdmin upgrade.

What happened

Leaked admin key led to a malicious ProxyAdmin upgrade.

Transaction-level mechanics

Public post-incident disclosures do not include full transaction calldata or execution traces for this incident.

TODO: Add exact Safe transaction hash, decoded actions, and the on-chain state changes once verified primary sources are available. For now, the attack vector summary above is derived from public reporting.

What independent decoding / hash verification / config scanning would have caught

Not a Safe-signing failure, but implementation/upgrade monitoring of the pattern this tool checks would have flagged the ProxyAdmin change instantly.

Verdict

Could have helped partially