MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Ex-Employee Hacks Bedrock UniBTC for $2M: Fuzzland Uncovers Insider Exploit | DeFi hack | CryptoRank.io
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,191.002.97%
  • ethereumEthereum(ETH)$2,419.453.19%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.482.11%
  • binancecoinBNB(BNB)$643.941.37%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$88.830.00%
  • tronTRON(TRX)$0.3281860.44%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.21%
  • dogecoinDogecoin(DOGE)$0.0994420.53%
Blockchain Security

Ex-Employee Hacks Bedrock UniBTC for $2M: Fuzzland Uncovers Insider Exploit | DeFi hack | CryptoRank.io

Last updated: June 25, 2025 8:20 pm
Published: 10 months ago
Share

Fuzzland has disclosed a $2 million insider attack that targeted Bedrock’s UniBTC protocol in September 2024, was carried out by a former employee who used malware, social engineering, and privileged access to compromise internal systems.

Fuzzland has taken full responsibility for the breach and reimbursed all affected parties.

Fuzzland, in a post on X, revealed that a past employee exploited the UniBTC protocol via a sophisticated insider operation. The individual joined the company under the guise of a skilled MEV developer and later inserted a trojan into Fuzzland’s MEV codebase using a malicious Rust crate named rands.

The attack vector began with social engineering. The former employee impressed during interviews and demonstrated a functioning MEV bot, earning access to the company’s infrastructure.

On September 4, 2024, the attacker modified the project’s Cargo.toml file to include the trojan, which auto-executed in commonly used IDEs such as VSCode and JetBrains.

The malware allowed persistent, undetected access to engineering workstations for over three weeks. Security tools such as Falcon and AVG failed to detect the intrusion.

However, on September 26, Fuzzland discussed a vulnerability in UniBTC, discovered in a Dedaub report, during an emergency call. Just over an hour later, at 18:28 UTC, the UniBTC protocol was exploited.

In response, Fuzzland compensated Bedrock for its losses using company funds. The firm enlisted Web3 security firm zeroShadow to investigate the breach and rule out any internal collusion. It also filed reports with both the FBI and Chinese law enforcement to pursue criminal action.

Despite the attack, Bedrock’s total value locked (TVL) grew from $240 million in September 2024 to $535 million in June 2025, according to DeFiLlama data.

To safeguard its systems from future incidence, Fuzzland launched new internal controls and adopted enhanced vetting procedures.

This includes on-site employee screenings, detailed know-your-employee (KYE) verification, and strict privilege separation. Sensitive systems remain isolated, and private keys are secured in trusted execution environments (TEEs).

According to its report, Fuzzland has implemented software bill of materials (SBOM) checks across all codebases. This ensures that any malicious dependencies are flagged before deployment.

Fuzzland also expanded its source code analysis capabilities by integrating tools like CodeQL and CodeRabbit.

Additionally, Fuzzland reinforced its protocols for handling intelligence under TLP:RED, ensuring strict need-to-know access for vulnerability information.

Fuzzland also acknowledged the contributions of Bedrock, SEAL 911, Slowmist, and zeroShadow in coordinating a swift response. It shared threat indicators such as suspicious IP addresses and malware samples on VirusTotal to assist the broader security community.

Notably, the crypto industry continues to see a rise in crypto hacks driven by phishing and social engineering. Blockchain security firm CertiK reported that over $364 million was stolen in April 2025. This amounted to a 1,163% surge from the $28.8 million stolen in March.

In one of the year’s most severe breaches, hackers stole 3,520 Bitcoins worth $330.7 million from a U.S. senior citizen.

Meanwhile, the biggest hack to date remains the Bybit hack on February 21. The exchange suffered a major security breach, resulting in hack of a $1.5 billion worth of ETH.

Read more on CryptoRank

This news is powered by CryptoRank CryptoRank

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Crypto investor loses $1M in Uniswap scam exploiting Ethereum’s EIP-7702
Prediction markets hit $64 billion in 2025 but reliance on centralized logins has created a critical security flaw | Market Analysis | CryptoRank.io
Qubic Gains Majority Hashrate Control Over Monero, Triggering Network Security Concerns News ETHNews
The Crypto Roundup: 07 October 2025 | CryptoCompare.com
Best Crypto Presale Projects to Buy Now Before TGE and Exchange Listings

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Coinsilium Group Limited: Forza! Bitcoin Treasury Update | Company Announcement | Investegate
Next Article Ex-Employee Hacks Bedrock UniBTC for $2M: Fuzzland Uncovers Insider Exploit
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d