RISEx lost $673,011 in USDC.e to an access control bug on August 3. Eight days later, on-chain records show the attacker’s wallet has not moved a single token.

The perpetuals exchange caught the theft in minutes. RISE’s own block explorer shows the drain and the patch landing forty-eight minutes apart, at 07:21 and 08:09 UTC. XLP depositors got made whole from July’s trading fees before most of them even noticed a problem.

The Adapter That Trusted Everyone

RISEx’s own statement called it a misconfiguration in the RWA strategy, present since deployment on July 13. An independent on-chain researcher going by lin4o dug further and found the actual mechanism: an authority module named PermissiveAuthority, sitting on the RISExAdapter contract, that let any address call emergencyWithdraw, not only the one allowed strategy contract it was built for.

The attacker did not need a stolen key or a bridge failure. A helper contract, deployed for the occasion, called the function directly. Three weeks of exposure ended in one transaction.

Independent researcher's technical thread naming the PermissiveAuthority access control bug
X/lin4o (@l1nnno) — independent technical breakdown naming the PermissiveAuthority access control bug on the RISExAdapter contract, screenshotted August 11, 2026.
RISEx official statement on X about the August 3 unauthorized withdrawal
X/RISEx — official incident statement posted by @risextrade, screenshotted August 11, 2026.

Where The Money Actually Went

RISE’s mainnet explorer puts the figure at 673,011.565895 USDC.e, drained from the strategy pool in a single transaction and routed through an executor contract before splitting across chains. 349,999 USDC crossed to Ethereum. 323,010.57 USDC.e crossed to Base. Two dollars went to bridge fees along the way, an oddly tidy detail for a theft this size.

RISE Mainnet block explorer showing the exploit transaction and token transfers
RISE Mainnet Explorer — transaction 0xc52560be…ace3e987 showing the 673,011.565895 USDC.e drain and its onward routing, screenshotted August 11, 2026.

A Week Of Silence On Etherscan

CryptoNewsLive traced the Ethereum-side wallet independently. Funded by. That is the label Etherscan shows on the recipient address, and the funding wallet matches, almost to the letter, the address RISEx itself named as the incident’s initiator. Two transactions total sit on that account. Both inbound. Zero outbound.

The wallet still holds $349,885.25 in tokens as of this check. Add the Base side of the split and the multichain total comes to $672,786.48, functionally the entire haul, sitting untouched since August 4.

Etherscan page for the attacker's Ethereum wallet showing funded-by label and zero outbound transactions
Etherscan — the Ethereum-side recipient wallet, funded by the same address RISEx named as the incident initiator, still holding $349,885.25 with zero outbound transactions, screenshotted August 11, 2026.

Nobody Big Is Watching This One

PeckShield, SlowMist, CertiK Alert, Cyvers, BlockSec. None of the five posted about it, not once in eight days. A targeted search across all five accounts on X turned up zero results naming RISEx or the exploit. For a $673,000 loss, that is a quiet trail, and it left the only real-time account of what happened to an independent researcher working from public data, not a named security firm.

X search showing zero results for RISEx from major security firm accounts
X search — zero results for RISEx across PeckShieldAlert, SlowMist_Team, CertiKAlert, CyversAlerts and BlockSecTeam, screenshotted August 11, 2026.

The Chain RISEx Basically Is

RISE Chain carries $16.39 million in total DeFi value locked, and RISEx alone accounts for $16.38 million of it. There is barely a second protocol worth counting. Galaxy Digital backs the exchange, DefiLlama ranks it 16th among the 370 derivatives protocols it tracks, and the platform processed 2.774 billion dollars in perpetual futures volume over the past 30 days against just $39.54 million in open interest.

Total value locked climbed 27.5% over that same month, hack included. Nobody pulled their money.

DeFiLlama RISE chain page showing RISEx as nearly all of the chain's TVL
DeFiLlama RISE chain page — RISEx accounting for $16.38 million of RISE Chain’s $16.39 million total DeFi TVL, screenshotted August 11, 2026.
DeFiLlama RISEx protocol page showing 30-day perp volume, open interest and TVL trend
DeFiLlama RISEx protocol page — 30-day perpetual futures volume, open interest and the TVL trend since the hack, screenshotted August 11, 2026.

The Promised Postmortem Has Not Landed

RISEx said in its own statement that “a postmortem will be published.” Eight days on, no dedicated write-up has gone out from the account, only the original incident thread and a repeated reminder that @risextrade remains the only official source. No recovery form exists. No claim process either, a warning the exchange issued before anyone had the chance to fake one.

Whether the attacker ever moves the $672,786 still sitting on Ethereum, or sends it back the way RISEx keeps hoping, is an open question the exchange cannot answer yet. The chain’s own explorer, per DeFiLlama’s hacks database and RISEx’s own tracked metrics, will show it the moment it happens.