Futureswap exploited again as hackers steal $74,000 via reentrancy bug

Source Cryptopolitan

Decentralized leverage trading platform Futureswap has been exploited for a second time in four days, with the hackers stealing an estimated $74,000 this time around.

Blockchain security firm BlockSec Phalcon disclosed the second attack on X, revealing that attackers had exploited a new vulnerability in the same contract they had targeted just days earlier. The security firm noted that “while the loss is not large, the interesting part is that a new attack surface appeared: a reentrancy vulnerability.”

The attacker employed a two-step process involving Futureswap’s mandatory three-day cooldown period to systematically drain funds.

According to Phalcon, BlockSec’s threat detection platform, the attacker first re-entered the 0x5308fcb1 function before the contract updated its internal accounting. Then the “attacker minted an excessive amount of LP tokens relative to the assets actually deposited.”

After waiting out the withdrawal cooldown, the attacker burned the illicitly minted tokens to redeem the underlying collateral, effectively siphoning assets from the protocol along with the profit.

Futureswap is hacked for the third time in one month

The latest attack comes a few days after the platform lost over $395,000 in an exploit that popped up BlockSec’s Phalcon’s radar. The attackers that participated in that exploit stole the funds through multiple changePosition operations. That incident appeared related to unexpected stableBalance accounting changes during position updates that later allowed USDC to be released when removing collateral.

Futureswap also suffered a governance attack in December 2025 that netted attackers at least $830,000. In that incident, hackers used a flash loan to temporarily borrow governance tokens, gaining voting power to pass a malicious proposal that transferred funds from the protocol.

Futureswap has so far lost over $1 million cumulatively across three separate attacks that have leveraged different vulnerabilities on the platform.

Legacy DeFi protocols under siege

The Futureswap incidents form part of the over $27 million lost to hackers who continue to target legacy DeFi platforms into 2026.

Other Arbitrum-based protocols have suffered similar fates in recent weeks. In early January, USDGambit and TLP lost $1.5 million when attackers gained admin access and deployed malicious smart contracts. TMX Tribe suffered a $1.4 million exploit, while the IPOR Fusion USDC vault lost $336,000 through a legacy contract vulnerability, though it has pledged to fully reimburse affected users.

Despite the security breaches that have hit protocols based on Arbitrum, the layer-2 blockchain still holds over $3.1 billion in total value locked in DeFi, which some analysts may say is part of what makes it an attractive target for attackers.

The network has remained near the top position among Ethereum Layer-2 solutions in terms of total value locked since launching in 2021.

What’s going on at the Futureswap camp?

Nobody on the Futureswap team has released a statement concerning the exploits. The last post on the platform’s X account dates to 2023, and the protocol is said to have been last audited in 2021.

The case raises difficult questions about responsibility when protocols are abandoned but continue to hold user funds. Security experts recommend that teams either properly deprecate and sunset legacy contracts or conduct fresh security audits and verify source code.

Users, meanwhile, are advised to withdraw assets from older contracts showing signs of abandonment.

Sharpen your strategy with mentorship + daily ideas - 30 days free access to our trading program

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
US Dollar Index steadies above 99.00 ahead of Retail Sales, PPI dataThe US Dollar Index (DXY), which measures the value of the US Dollar (USD) against six major currencies, is inching lower after registering modest gains in the previous session. The DXY hovers around 99.10 during the Asian hours on Wednesday.
Author  FXStreet
9 hours ago
The US Dollar Index (DXY), which measures the value of the US Dollar (USD) against six major currencies, is inching lower after registering modest gains in the previous session. The DXY hovers around 99.10 during the Asian hours on Wednesday.
placeholder
Bitcoin Eyes $92K Breakout as Stocks Reach Fresh Records on Soft US CPI DataBitcoin nears $93,000 as lower-than-expected US inflation data supports a surge in risk assets.
Author  Mitrade
17 hours ago
Bitcoin nears $93,000 as lower-than-expected US inflation data supports a surge in risk assets.
placeholder
Gold Price Forectast: XAU/USD rises above $4,600 on US rate cut expectations, Fed uncertainty Gold price (XAU/USD) rises to around $4,600 during the early Asian session on Wednesday. The precious metal gains momentum as traders firm up bets on US interest rate cuts after the release of inflation data.
Author  FXStreet
18 hours ago
Gold price (XAU/USD) rises to around $4,600 during the early Asian session on Wednesday. The precious metal gains momentum as traders firm up bets on US interest rate cuts after the release of inflation data.
placeholder
Bank Stocks Lead US Equities in 2026; Wall Street Warns Guidance Matters More Than Earnings.Bank stocks will release fourth-quarter earnings this week, kicking off the 2026 U.S. earnings season.Tuesday will see JPMorgan Chase (JPM) reporting earnings, while Citigroup (C) , Wells
Author  TradingKey
Yesterday 10: 15
Bank stocks will release fourth-quarter earnings this week, kicking off the 2026 U.S. earnings season.Tuesday will see JPMorgan Chase (JPM) reporting earnings, while Citigroup (C) , Wells
placeholder
Bitwise Slams 401(k) Bitcoin Ban as ‘Ridiculous’ Amid Warren’s Pressure on SECU.S. President Donald Trump's executive order has paved the way for cryptocurrencies to be included in 401(k) retirement plans, igniting debate on their volatility.
Author  Mitrade
Yesterday 08: 34
U.S. President Donald Trump's executive order has paved the way for cryptocurrencies to be included in 401(k) retirement plans, igniting debate on their volatility.
goTop
quote