MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: CrediX Finance Exploited For $4.5 Million In Governance Attack – FinanceFeeds
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$78,349.000.13%
  • ethereumEthereum(ETH)$2,328.95-1.45%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.441.16%
  • binancecoinBNB(BNB)$638.340.12%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$86.13-0.22%
  • tronTRON(TRX)$0.328159-0.47%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.46%
  • dogecoinDogecoin(DOGE)$0.0977961.88%
Blockchain Security

CrediX Finance Exploited For $4.5 Million In Governance Attack – FinanceFeeds

Last updated: August 4, 2025 7:40 pm
Published: 9 months ago
Share

CrediX Finance, a decentralized lending protocol on the Sonic blockchain, was exploited on August 4, 2025, resulting in the loss of approximately $4.5 million in user funds. The attacker exploited a critical governance vulnerability that granted them elevated permissions through the protocol’s multisignature wallet system.

According to reports from blockchain security firm SlowMist, the attacker was added to CrediX’s multisig as a signer six days before the incident occurred. This individual or entity was then granted both “Admin” and “Bridge” roles through the ACLManager — CediX’s core access control module. These privileges allowed the attacker to mint uncollateralized assets and borrow against them, effectively draining the platform’s lending pool.

PeckShield later confirmed the attack vector, identifying the compromised wallet (ending in ) as the one that carried out the exploit. With bridge and admin-level access, the attacker manipulated the token minting process, generated synthetic collateral, and used it to take out a series of flash loans and transfers that removed funds from the protocol. Once extracted, the funds were bridged from Sonic to Ethereum and dispersed across three separate wallets, where they remain as of this writing.

In response to the breach, CrediX took immediate action by disabling its web application and halting all on-chain operations. A statement issued via the protocol’s official X (formerly Twitter) account acknowledged the attack and confirmed that the team was working on recovering funds. They promised users a full reimbursement within 24 to 48 hours, although details of the recovery plan have not been disclosed.

The attacker’s initial withdrawal amounted to roughly $2.64 million — believed to be seeded via Tornado Cash — before escalating the exploit to its full $4.5 million impact. Investigators at CertiK and other security firms are monitoring the attacker wallets and analyzing fund movements in hopes of tracking or freezing the stolen assets.

The incident has renewed scrutiny of the role of multisig wallets in DeFi governance. While multisigs are often seen as a security layer, this attack demonstrates how misconfigured access controls can quickly lead to catastrophic loss. CrediX’s decision to grant sweeping administrative permissions to a single new multisig signer without broader protocol approval has raised questions about its internal governance structure and security protocols.

The CrediX exploit is the latest in a string of DeFi-related attacks in 2025, many of which have targeted governance or administrative layers rather than codebase flaws. As protocols race to launch products and attract liquidity, security audits and decentralized governance implementations have struggled to keep pace.

Analysts warn that governance-based vulnerabilities will continue to be a systemic risk for emerging DeFi platforms. The CrediX attack underscores the need for real-time access monitoring, role-based permission segmentation, and mandatory community-based approval systems for critical changes.

With the broader DeFi ecosystem already under regulatory and public scrutiny, exploits like this threaten to undermine trust in decentralized finance at a critical time for its mainstream adoption.

Read more on FinanceFeeds

This news is powered by FinanceFeeds FinanceFeeds

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

$3.85 Million in Ethereum From Mixin Network Hack Sent to Tornado Cash – Decrypt
XRP and PEPE Are Range-Bound for Now, Traders Call Another Token With at Least 20x ROI Potential
Aptos Price Prediction: How Quantum-Resistant Security Could Impact APT in 2025
Crypto Influencer Sillytuna Loses $24M in Address Poisoning Scam — How It Happened
India forges strategic digital partnership with Philippines

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Ahmedabad Lights Up India’s Web3 Map as India Blockchain Tour Rolls Into Town
Next Article CrediX Finance hacked for $4.5m via governance flaw
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d