RISEx lost $673,011 in USDC.e to an access control bug on August 3. Eight days later, on-chain records show the attacker’s wallet has not moved a single token.
The perpetuals exchange caught the theft in minutes. RISE’s own block explorer shows the drain and the patch landing forty-eight minutes apart, at 07:21 and 08:09 UTC. XLP depositors got made whole from July’s trading fees before most of them even noticed a problem.
The Adapter That Trusted Everyone
RISEx’s own statement called it a misconfiguration in the RWA strategy, present since deployment on July 13. An independent on-chain researcher going by lin4o dug further and found the actual mechanism: an authority module named PermissiveAuthority, sitting on the RISExAdapter contract, that let any address call emergencyWithdraw, not only the one allowed strategy contract it was built for.
The attacker did not need a stolen key or a bridge failure. A helper contract, deployed for the occasion, called the function directly. Three weeks of exposure ended in one transaction.


Where The Money Actually Went
RISE’s mainnet explorer puts the figure at 673,011.565895 USDC.e, drained from the strategy pool in a single transaction and routed through an executor contract before splitting across chains. 349,999 USDC crossed to Ethereum. 323,010.57 USDC.e crossed to Base. Two dollars went to bridge fees along the way, an oddly tidy detail for a theft this size.

A Week Of Silence On Etherscan
CryptoNewsLive traced the Ethereum-side wallet independently. Funded by. That is the label Etherscan shows on the recipient address, and the funding wallet matches, almost to the letter, the address RISEx itself named as the incident’s initiator. Two transactions total sit on that account. Both inbound. Zero outbound.
The wallet still holds $349,885.25 in tokens as of this check. Add the Base side of the split and the multichain total comes to $672,786.48, functionally the entire haul, sitting untouched since August 4.

Nobody Big Is Watching This One
PeckShield, SlowMist, CertiK Alert, Cyvers, BlockSec. None of the five posted about it, not once in eight days. A targeted search across all five accounts on X turned up zero results naming RISEx or the exploit. For a $673,000 loss, that is a quiet trail, and it left the only real-time account of what happened to an independent researcher working from public data, not a named security firm.

The Chain RISEx Basically Is
RISE Chain carries $16.39 million in total DeFi value locked, and RISEx alone accounts for $16.38 million of it. There is barely a second protocol worth counting. Galaxy Digital backs the exchange, DefiLlama ranks it 16th among the 370 derivatives protocols it tracks, and the platform processed 2.774 billion dollars in perpetual futures volume over the past 30 days against just $39.54 million in open interest.
Total value locked climbed 27.5% over that same month, hack included. Nobody pulled their money.


The Promised Postmortem Has Not Landed
RISEx said in its own statement that “a postmortem will be published.” Eight days on, no dedicated write-up has gone out from the account, only the original incident thread and a repeated reminder that @risextrade remains the only official source. No recovery form exists. No claim process either, a warning the exchange issued before anyone had the chance to fake one.
Whether the attacker ever moves the $672,786 still sitting on Ethereum, or sends it back the way RISEx keeps hoping, is an open question the exchange cannot answer yet. The chain’s own explorer, per DeFiLlama’s hacks database and RISEx’s own tracked metrics, will show it the moment it happens.












