{"investigation":{"slug":"concentric","entity_name":"Concentric","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Concentric (Concentric.fi) was an automated liquidity management protocol built on Camelot v3 on the Arbitrum network, offering vault-based yield optimization for concentrated liquidity positions. On January 22, 2024, the protocol suffered a critical security breach when a team member's deployer wallet was compromised through a targeted social engineering attack, resulting in approximately $1.85 million in losses and a 57% crash in the CONE token price. The protocol was subsequently halted entirely, and blockchain forensics firm CertiK linked the exploiter's wallets to prior incidents targeting OKX, UnoRe, and LunaFi, suggesting a sophisticated and recurring threat actor.","sections":[{"content":"Concentric Finance (Concentric.fi) was an automated liquidity management protocol deployed on the Arbitrum Layer-2 network. The protocol was built on top of Camelot v3 and provided what it termed Active Liquidity Management (ALM), allowing users to deposit assets into algorithmic vaults that dynamically optimized positions across concentrated liquidity pools to maximize yield and minimize impermanent loss. The protocol issued a native utility token, CONE, which granted governance rights and protocol fee sharing through a dual-token system involving xCONE, subject to a six-month vesting period for full redemption. As of mid-2024 the CONE token is listed as not actively trading on major data aggregators, consistent with the protocol's operational halt following the January 2024 exploit.","heading":"Protocol Overview","sources":[{"url":"https://docs.concentric.fi","name":"docs.concentric.fi","type":"other","credibility":3},{"url":"https://docs.concentric.fi/overview/active-liquidity-management","name":"docs.concentric.fi","type":"other","credibility":3},{"url":"https://docs.concentric.fi/tokenomics/cone-token","name":"docs.concentric.fi","type":"other","credibility":3},{"url":"https://coincodex.com/crypto/concentric-fi/","name":"coincodex.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 22, 2024, Concentric Finance was exploited via a targeted social engineering attack against a team member who held access to the protocol's deployer wallet. The attacker obtained the private key associated with the deployer account (wallet address 0xeaf6), then transferred contract ownership to an attacker-controlled address (0x3F06). The attacker subsequently upgraded the Concentric vault contracts with a malicious implementation. Using the admin functions exposed by the upgrade, the attacker called adminMint() on CONE-1 vault contracts to mint LP tokens, then immediately called burn() to redeem the underlying ERC-20 assets from the associated AlgebraPool. This cycle was repeated across multiple vaults to systematically drain them. In a second phase of the attack, the attacker deployed a secondary contract that exploited existing user token approvals to Concentric contracts, sweeping an additional 65.4 ETH (approximately $155,503) from users who had granted permissions but had not yet revoked them. Total losses across both attack vectors amounted to approximately 780 ETH, valued at roughly $1.85 million at the time. The stolen ETH was converted and split across three receiving wallets. Concentric's team confirmed the breach via their official communications, stating: 'We regret to inform you that our protocol has suffered a severe security breach due to a targeted social engineering attack on one of our team members holding the deployer wallet.' The protocol was immediately halted in full following the incident. The team urged all users to revoke approvals on all vault contract addresses. A post-mortem report was committed to but no public evidence of a compensation plan for affected users was documented in contemporaneous reporting.","heading":"January 2024 Social Engineering Attack and Exploit","sources":[{"url":"https://crypto.news/concentric-app-suffers-1-7m-social-engineering-hack-on-arbitrum/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6ZxRxjsoFhsmRQwCZzLUK1-concentric-fi-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/concentricfi-confirms-security-breach-damage-estimated-1-6-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://beincrypto.com/concentricfi-security-break/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/concentric-finance-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Post-incident analysis by CertiK and other security researchers identified two structural vulnerabilities that made the attack possible and highly damaging. First, the vault contracts were designed to be upgradeable by a single deployer key with no multisignature requirement, creating a critical single point of failure. Even though Concentric's vaults had reportedly undergone prior security audits, the upgradeability mechanism itself — when controlled by a single externally-owned account (EOA) — meant that any compromise of that key would grant full control over all vault logic and user funds. Second, the absence of timelock or multisig governance over upgrades meant there was no delay or secondary approval required before a malicious upgrade could take effect. CertiK's report explicitly identified 'the absence of multisig-based administrative controls' and 'unnecessary upgradeability built into vault contracts' as the root causes enabling the scale of the exploit. These findings reflect a recognized category of DeFi risk in which centralized admin keys negate the security guarantees provided by smart contract audits.","heading":"Centralization and Architecture Risk Factors","sources":[{"url":"https://www.certik.com/resources/blog/6ZxRxjsoFhsmRQwCZzLUK1-concentric-fi-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/concentricfi-confirms-security-breach-damage-estimated-1-6-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://crypto.news/concentric-app-suffers-1-7m-social-engineering-hack-on-arbitrum/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain security firm CertiK published a detailed incident analysis linking the Concentric exploiter to multiple prior security incidents. The analysis identified that wallet 0xFD681A9aA555391Ef772C53144db8404AEC76030, which received funds from the Concentric exploit, had been publicly identified on Etherscan as associated with the OKX DEX exploit of December 13, 2023 — an incident that resulted in approximately $2.7 million in losses from an abandoned OKX market maker contract. Additionally, the wallet that funded the Concentric attacker (0x5A58D1a81c73Dc5f1d56bA41e413Ee5288c65d7F) was traced to the UnoRe exploit of 2023. CertiK's report also referenced connections to the LunaFi incident, though the specific on-chain linkage was not fully detailed in public reporting. In total, 300 ETH from the Concentric exploit was sent to an address already associated with the OKX attack, strengthening the hypothesis of a single threat actor or coordinated group responsible for a series of protocol compromises via social engineering and private key theft across 2023 and early 2024.","heading":"Connections to Prior Exploits: OKX DEX, UnoRe, and LunaFi","sources":[{"url":"https://www.certik.com/resources/blog/6ZxRxjsoFhsmRQwCZzLUK1-concentric-fi-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.tradingview.com/news/cryptobriefing:32c45c86e094b:0-concentric-s-1-8-million-exploiter-is-tied-to-okx-and-lunafi-incidents-certik-reports/","name":"tradingview.com","type":"other","credibility":3},{"url":"https://crypto-economy.com/concentricfi-falls-victim-to-1-6-million-exploit-unearths-ties-to-infamous-okx-attacker/","name":"crypto-economy.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following public disclosure of the exploit on January 22, 2024, the CONE token experienced a severe market reaction. Multiple sources reported an immediate decline of approximately 57%, with the token price reaching approximately $0.7571 at its post-incident low. The token is currently listed as not actively trading on CoinCodex, consistent with the protocol's operational halt. No evidence of exchange delistings, formal winding-down announcements, or compensation distributions to CONE holders was found in available public reporting.","heading":"CONE Token Market Impact","sources":[{"url":"https://beincrypto.com/concentricfi-security-break/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://coincodex.com/crypto/concentric-fi/","name":"coincodex.com","type":"other","credibility":3},{"url":"https://coinmooner.com/news/coinmooner-investigates-the-hack-of-concentricfi-hacker-attack-and-losses-of-1.8-million","name":"coinmooner.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediately after the exploit, Concentric Finance announced that 'the protocol will be entirely halted till a foreseeable future,' noting that the treasury held only 8 ETH and some residual USDC in a CONE-USDC LP at the time of the announcement. The team committed to publishing a formal post-mortem, but no public evidence of a user compensation plan, restitution fund, or protocol relaunch was identified in available sources as of the time of this investigation. The CONE token ceased active trading on major platforms. Users who had granted contract approvals to Concentric vaults were encouraged to revoke these permissions immediately. The protocol's operational shutdown and apparent lack of user recovery mechanisms represent a significant adverse outcome for participants.","heading":"Protocol Halt and Absence of Recovery Plan","sources":[{"url":"https://crypto.news/concentric-app-suffers-1-7m-social-engineering-hack-on-arbitrum/","name":"crypto.news","type":"other","credibility":3},{"url":"https://cryptobriefing.com/concentricfi-confirms-security-breach-damage-estimated-1-6-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/concentric-confirms-1-6m-private-key-breach-on-arbitrum-protocol/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT, the pseudonymous blockchain investigator known for tracking crypto exploits and flagging high-risk entities, is noted as having flagged Concentric as a risk entity in the AVOID.NET trust intelligence pipeline. The specific public posts or threads from ZachXBT directly addressing Concentric.fi were not independently verified in available search results at the time of this investigation, but the flagging is consistent with ZachXBT's documented pattern of tracking exploited DeFi protocols and entities connected to recurring threat actor wallets.","heading":"ZachXBT Flag","sources":[{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-12-13","event":"OKX DEX exploit occurs, resulting in approximately $2.7 million in losses. Wallet later connected to the Concentric attacker is involved in this incident.","source":""},{"date":"2024-01-22","event":"Concentric Finance exploited via social engineering attack on a team member's deployer wallet. Attacker upgrades vault contracts, mints LP tokens via adminMint(), drains vaults of approximately 715 ETH. A second phase sweeps 65.4 ETH from user approvals. Total losses approximately 780 ETH (~$1.85 million).","source":""},{"date":"2024-01-22","event":"Cyvers detects suspicious activity. CertiK publishes Skynet alert identifying the exploiter wallet as linked to the OKX exploit. Initial loss estimates cited as approximately $1.6 million, later revised upward.","source":""},{"date":"2024-01-22","event":"Concentric team confirms breach via official channels, urges all users to revoke approvals on vault contracts, halts the protocol entirely.","source":""},{"date":"2024-01-22","event":"CONE token price drops approximately 57% following public announcement of the exploit.","source":""},{"date":"2024-01-22","event":"CertiK publishes full incident analysis linking the exploiter to OKX, UnoRe, and LunaFi incidents, indicating a pattern of coordinated attacks.","source":""},{"date":"2024-01-22","event":"Protocol announced as halted indefinitely, with 8 ETH and residual USDC remaining in the treasury.","source":""}],"sources_used":[{"url":"https://docs.concentric.fi","name":"docs.concentric.fi","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.concentric.fi/overview/active-liquidity-management","name":"docs.concentric.fi","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.concentric.fi/tokenomics/cone-token","name":"docs.concentric.fi","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coincodex.com/crypto/concentric-fi/","name":"coincodex.com","type":"other","archive_url":"https://web.archive.org/web/20260829125128/https://coincodex.com/crypto/concentric-fi/","credibility":3,"archive_timestamp":"2026-08-29T12:51:28+00:00"},{"url":"https://crypto.news/concentric-app-suffers-1-7m-social-engineering-hack-on-arbitrum/","name":"crypto.news","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.certik.com/resources/blog/6ZxRxjsoFhsmRQwCZzLUK1-concentric-fi-incident-analysis","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829145106/https://www.certik.com/blog/6ZxRxjsoFhsmRQwCZzLUK1-concentric-fi-incident-analysis","credibility":3,"archive_timestamp":"2026-08-29T14:51:06+00:00"},{"url":"https://cryptobriefing.com/concentricfi-confirms-security-breach-damage-estimated-1-6-million/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260305180959/https://cryptobriefing.com/concentricfi-confirms-security-breach-damage-estimated-1-6-million/","credibility":3,"archive_timestamp":"2026-03-05T18:09:59+00:00"},{"url":"https://beincrypto.com/concentricfi-security-break/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/single/concentric-finance-exploit","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260829190725/https://www.web3isgoinggreat.com/single/concentric-finance-exploit","credibility":3,"archive_timestamp":"2026-08-29T19:07:25+00:00"},{"url":"https://www.tradingview.com/news/cryptobriefing:32c45c86e094b:0-concentric-s-1-8-million-exploiter-is-tied-to-okx-and-lunafi-incidents-certik-reports/","name":"tradingview.com","type":"other","archive_url":"https://web.archive.org/web/20260830011155/https://www.tradingview.com/news/cryptobriefing:32c45c86e094b:0-concentric-s-1-8-million-exploiter-is-tied-to-okx-and-lunafi-incidents-certik-reports/","credibility":3,"archive_timestamp":"2026-08-30T01:11:55+00:00"},{"url":"https://crypto-economy.com/concentricfi-falls-victim-to-1-6-million-exploit-unearths-ties-to-infamous-okx-attacker/","name":"crypto-economy.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinmooner.com/news/coinmooner-investigates-the-hack-of-concentricfi-hacker-attack-and-losses-of-1.8-million","name":"coinmooner.com","type":"other","archive_url":"https://web.archive.org/web/20260829182429/https://coinmooner.com/blog/news/coinmooner-investigates-the-hack-of-concentricfi-hacker-attack-and-losses-of-1.8-million","credibility":3,"archive_timestamp":"2026-08-29T18:24:29+00:00"},{"url":"https://cryptonews.com/news/concentric-confirms-1-6m-private-key-breach-on-arbitrum-protocol/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:35.655555+00:00","updated_at":"2026-08-30T05:14:08.57786+00:00"}}