• About
  • Landing Page
  • Buy JNews
Newsletter
Impact Crypto News
Advertisement
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
Impact Crypto News
No Result
View All Result
Home Crypto News Scam News

CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge

IMPACTCRYPTO by IMPACTCRYPTO
August 4, 2025
in Scam News
56 2
0
CrediX hack adds to .1 billion DeFi losses in 2025 as multisig failures surge
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


CrediX hack adds to .1 billion DeFi losses in 2025 as multisig failures surge
  • Attacker gained admin access six days before attack.
  • Borrowed $2.64 million after minting fake collateral tokens.
  • Hacken urges real-time AI monitoring for DeFi wallet security.

The decentralised finance sector has once again been shaken by a major exploit—this time targeting CrediX.

The project reportedly lost $4.5 million following an attack enabled by a private key compromise and governance access flaws.

The attacker bridged funds across networks, exploited administrative access, and drained the CrediX Pool using minted collateral tokens.

The incident has added to mounting concerns over the security of multisig wallets, which have accounted for most of the $3.1 billion in crypto losses so far in 2025.

Funds bridged from Sonic to Ethereum as platform taken offline

CrediX has since taken its website offline to prevent further deposits.

Blockchain security firm CertiK confirmed that the stolen funds were transferred from the Sonic network to Ethereum.

Web3 security platform Cyvers Alerts flagged multiple suspicious transactions on Sonic, tracing one address funded via Tornado Cash on Ethereum.

This address bridged funds to Sonic and borrowed approximately $2.64 million from CrediX.

These funds were likely extracted using collateral tokens that the attacker minted after gaining backdoor access.

Admin access and bridge rights enabled token minting exploit

According to SlowMist, an on-chain security provider, the attacker was granted Admin and Bridge roles within the CrediX Multisig Wallet six days prior to the exploit.

These roles were assigned using the protocol’s ACLManager.

With Bridge-level access, the attacker was able to mint collateral tokens through the CrediX Pool, which were then used to borrow assets and ultimately drain the protocol.

This type of exploit underlines a critical risk in decentralised governance models, particularly around role-based access control.

Inadequate oversight in assigning privileges, especially in multisig environments, leaves DeFi protocols highly exposed to internal or external compromise.

Multisig wallets linked to most 2025 crypto losses

The CrediX incident is part of a broader trend this year.

A report by security firm Hacken states that $3.1 billion in crypto was lost in the first half of 2025, with the majority of cases involving multisig wallets.

These wallets were often breached through social engineering tactics, fake interfaces, or misconfigured signer setups.

The largest known attack this year remains the $1.46 billion Bybit exploit, where attackers deceived multisig signers using a spoofed interface.

Real-time threat detection now a priority, says Hacken

In response to the growing frequency of such incidents, Hacken has recommended moving away from traditional one-time security audits.

Instead, the firm advocates for real-time, AI-based security systems that monitor multisig activity and flag abnormal behaviour instantly.

According to Hacken, more than 80% of crypto losses this year stemmed from access control failures.

The firm urges platforms to implement stricter signer training, enforce tighter rule-based automation, and treat interfaces and signers as integral to system security.

Meanwhile, CrediX has said it aims to recover the stolen funds within 24–48 hours, though no further details have been provided at this time.


Share this article

Categories

Tags



Source link

Related articles

Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight

Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight

December 11, 2025
Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

December 10, 2025
Tags: AddsBillionbitcoin newsCredixcrypto analysiscrypto newsDeFiEthoz EdgefailureshackLatest bitcoin newslatest crypto newsLossesMultiSigsurge
Share76Tweet47

Related Posts

Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight

Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight

by IMPACTCRYPTO
December 11, 2025
0

Do Kwon faces sentencing in New York, reviving focus on the TerraUSD collapse. Prosecutors seek 12 years; defense asks for...

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

Binance CEO hacked by cell carrier exploit that likely leaves your own crypto exposed

by IMPACTCRYPTO
December 10, 2025
0

Binance co-CEO Yi He said her WeChat account was hijacked on Dec. 10 after a cell number tied to the...

Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

Silk Road crypto activity resurfaces as dormant Bitcoin wallets move again

by IMPACTCRYPTO
December 10, 2025
0

Silk Road-tagged wallets sent $3.14 million in Bitcoin across 176 transfers this week. The transactions are the most significant Silk...

Fake DBS crypto app scam exposes rising investor risks in India

Fake DBS crypto app scam exposes rising investor risks in India

by IMPACTCRYPTO
December 8, 2025
0

Retired engineer loses ₹1.28 crore to a fake trading app promoted through a WhatsApp investment group. Police warn of rising...

US crackdown exposes Burma crypto scam network using fake trading sites

US crackdown exposes Burma crypto scam network using fake trading sites

by IMPACTCRYPTO
December 3, 2025
0

DOJ seizes Burma-linked trading domains used for major crypto scam operations. Fraud network tied to Tai Chang compound used fake...

Load More

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0

© 2018 JNews by Jegtheme.