Wednesday, September 10, 2025
No Result
View All Result
Crypto Waffle
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
No Result
View All Result
Crypto Waffle
No Result
View All Result

CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge – CoinJournal

August 4, 2025
in Scam Alert
Reading Time: 3 mins read
0 0
A A
0
Home Scam Alert
Share on FacebookShare on Twitter


Attacker gained admin access six days before attack.
Borrowed $2.64 million after minting fake collateral tokens.
Hacken urges real-time AI monitoring for DeFi wallet security.

The decentralised finance sector has once again been shaken by a major exploit—this time targeting CrediX.

The project reportedly lost $4.5 million following an attack enabled by a private key compromise and governance access flaws.

The attacker bridged funds across networks, exploited administrative access, and drained the CrediX Pool using minted collateral tokens.

The incident has added to mounting concerns over the security of multisig wallets, which have accounted for most of the $3.1 billion in crypto losses so far in 2025.

Funds bridged from Sonic to Ethereum as platform taken offline

CrediX has since taken its website offline to prevent further deposits.

Blockchain security firm CertiK confirmed that the stolen funds were transferred from the Sonic network to Ethereum.

Web3 security platform Cyvers Alerts flagged multiple suspicious transactions on Sonic, tracing one address funded via Tornado Cash on Ethereum.

This address bridged funds to Sonic and borrowed approximately $2.64 million from CrediX.

These funds were likely extracted using collateral tokens that the attacker minted after gaining backdoor access.

Admin access and bridge rights enabled token minting exploit

According to SlowMist, an on-chain security provider, the attacker was granted Admin and Bridge roles within the CrediX Multisig Wallet six days prior to the exploit.

These roles were assigned using the protocol’s ACLManager.

With Bridge-level access, the attacker was able to mint collateral tokens through the CrediX Pool, which were then used to borrow assets and ultimately drain the protocol.

This type of exploit underlines a critical risk in decentralised governance models, particularly around role-based access control.

Inadequate oversight in assigning privileges, especially in multisig environments, leaves DeFi protocols highly exposed to internal or external compromise.

Multisig wallets linked to most 2025 crypto losses

The CrediX incident is part of a broader trend this year.

A report by security firm Hacken states that $3.1 billion in crypto was lost in the first half of 2025, with the majority of cases involving multisig wallets.

These wallets were often breached through social engineering tactics, fake interfaces, or misconfigured signer setups.

The largest known attack this year remains the $1.46 billion Bybit exploit, where attackers deceived multisig signers using a spoofed interface.

Real-time threat detection now a priority, says Hacken

In response to the growing frequency of such incidents, Hacken has recommended moving away from traditional one-time security audits.

Instead, the firm advocates for real-time, AI-based security systems that monitor multisig activity and flag abnormal behaviour instantly.

According to Hacken, more than 80% of crypto losses this year stemmed from access control failures.

The firm urges platforms to implement stricter signer training, enforce tighter rule-based automation, and treat interfaces and signers as integral to system security.

Meanwhile, CrediX has said it aims to recover the stolen funds within 24–48 hours, though no further details have been provided at this time.

Share this articleCategoriesTags



Source link

Tags: addsbillionCoinJournalCrediXDeFifailureshacklossesmultisigsurge
Previous Post

400 TPS and “Ethereum on your phone”: Vitalik Buterin & Tomasz K. Stańczak dropped big news at ETHKyiv 2025

Next Post

Deprecating Leveraged Tokens

Related Posts

Ethereum smart contracts quietly push javascript malware targeting developers
Scam Alert

Ethereum smart contracts quietly push javascript malware targeting developers

September 4, 2025
Venus Protocol suspends platform after phishing scam drains  million, XVS falls 6%
Scam Alert

Venus Protocol suspends platform after phishing scam drains $27 million, XVS falls 6%

September 2, 2025
Crypto hacks in August hit 3 million as exchange risks grow – CoinJournal
Scam Alert

Crypto hacks in August hit $163 million as exchange risks grow – CoinJournal

September 1, 2025
South Korea cracks down on crypto scam after BTS star Jungkook hit in 39 billion hack – CoinJournal
Scam Alert

South Korea cracks down on crypto scam after BTS star Jungkook hit in 39 billion hack – CoinJournal

August 29, 2025
FTT jumps 7% as Backpack launches platform to help FTX victims liquidate claims – CoinJournal
Scam Alert

FTT jumps 7% as Backpack launches platform to help FTX victims liquidate claims – CoinJournal

July 18, 2025
Inside the M Nobitex hack: a layer-by-layer breakdown – CoinJournal
Scam Alert

Inside the $90M Nobitex hack: a layer-by-layer breakdown – CoinJournal

June 28, 2025
Next Post
Deprecating Leveraged Tokens

Deprecating Leveraged Tokens

Protocol Update 001 – Scale L1 | Ethereum Foundation Blog

Protocol Update 001 – Scale L1 | Ethereum Foundation Blog

SEC staff statement on liquid staking may pave way for staking in spot Ether ETFs – CoinJournal

SEC staff statement on liquid staking may pave way for staking in spot Ether ETFs - CoinJournal

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • USD
  • EUR
  • GBP
  • AUD
  • JPY
  • bitcoinBitcoin(BTC)
    $112,355.00
  • ethereumEthereum(ETH)
    $4,327.36
  • rippleXRP(XRP)
    $2.97
  • tetherTether(USDT)
    $1.00
  • binancecoinBNB(BNB)
    $883.71
  • solanaSolana(SOL)
    $220.16
  • usd-coinUSDC(USDC)
    $1.00
  • staked-etherLido Staked Ether(STETH)
    $4,321.92
  • dogecoinDogecoin(DOGE)
    $0.240554
  • cardanoCardano(ADA)
    $0.87
Facebook Twitter Instagram Youtube RSS
Crypto Waffle

Your go-to source for the freshest cryptocurrency news, in-depth analysis, market trends, and expert insights.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Web3

SITEMAP

  • About us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$112,355.00-0.35%
  • ethereumEthereum(ETH)$4,327.36-0.63%
  • rippleXRP(XRP)$2.97-1.21%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$883.710.10%
  • solanaSolana(SOL)$220.160.82%
  • usd-coinUSDC(USDC)$1.000.00%
  • staked-etherLido Staked Ether(STETH)$4,321.92-0.66%
  • dogecoinDogecoin(DOGE)$0.240554-0.44%
  • cardanoCardano(ADA)$0.87-1.26%

Powered by
...
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by