Close Menu
Chain Tech Daily

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    FLUID price rallies as Fluid DEX dominates stablecoin swaps across Ethereum and L2s

    August 4, 2025

    Where could Pepeto and XRP go if Bitcoin hits $21m?

    August 4, 2025

    Scammers using AI tools to steal crypto via deepfakes and wallet drainers

    August 4, 2025
    Facebook X (Twitter) Instagram
    Chain Tech Daily
    • Altcoins
      • Litecoin
      • Coinbase
      • Crypto
      • Blockchain
    • Bitcoin
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Chain Tech Daily
    Home » CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge
    Ethereum

    CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge

    Olivia MartinezBy Olivia MartinezAugust 4, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cetus Protocol Hack Impacted Price

    • Attacker gained admin access six days before attack.
    • Borrowed $2.64 million after minting fake collateral tokens.
    • Hacken urges real-time AI monitoring for DeFi wallet security.

    The decentralised finance sector has once again been shaken by a major exploit—this time targeting CrediX.

    The project reportedly lost $4.5 million following an attack enabled by a private key compromise and governance access flaws.



    The attacker bridged funds across networks, exploited administrative access, and drained the CrediX Pool using minted collateral tokens.

    The incident has added to mounting concerns over the security of multisig wallets, which have accounted for most of the $3.1 billion in crypto losses so far in 2025.

    Funds bridged from Sonic to Ethereum as platform taken offline

    CrediX has since taken its website offline to prevent further deposits.

    Blockchain security firm CertiK confirmed that the stolen funds were transferred from the Sonic network to Ethereum.

    Web3 security platform Cyvers Alerts flagged multiple suspicious transactions on Sonic, tracing one address funded via Tornado Cash on Ethereum.

    This address bridged funds to Sonic and borrowed approximately $2.64 million from CrediX.

    These funds were likely extracted using collateral tokens that the attacker minted after gaining backdoor access.

    Admin access and bridge rights enabled token minting exploit

    According to SlowMist, an on-chain security provider, the attacker was granted Admin and Bridge roles within the CrediX Multisig Wallet six days prior to the exploit.

    These roles were assigned using the protocol’s ACLManager.

    With Bridge-level access, the attacker was able to mint collateral tokens through the CrediX Pool, which were then used to borrow assets and ultimately drain the protocol.

    This type of exploit underlines a critical risk in decentralised governance models, particularly around role-based access control.

    Inadequate oversight in assigning privileges, especially in multisig environments, leaves DeFi protocols highly exposed to internal or external compromise.

    Multisig wallets linked to most 2025 crypto losses

    The CrediX incident is part of a broader trend this year.

    A report by security firm Hacken states that $3.1 billion in crypto was lost in the first half of 2025, with the majority of cases involving multisig wallets.

    These wallets were often breached through social engineering tactics, fake interfaces, or misconfigured signer setups.

    The largest known attack this year remains the $1.46 billion Bybit exploit, where attackers deceived multisig signers using a spoofed interface.

    Real-time threat detection now a priority, says Hacken

    In response to the growing frequency of such incidents, Hacken has recommended moving away from traditional one-time security audits.

    Instead, the firm advocates for real-time, AI-based security systems that monitor multisig activity and flag abnormal behaviour instantly.

    According to Hacken, more than 80% of crypto losses this year stemmed from access control failures.

    The firm urges platforms to implement stricter signer training, enforce tighter rule-based automation, and treat interfaces and signers as integral to system security.

    Meanwhile, CrediX has said it aims to recover the stolen funds within 24–48 hours, though no further details have been provided at this time.


    Share this article

    Categories

    Tags



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Olivia Martinez

    Related Posts

    Ethereum July 31, 2025

    10 Years of Ethereum | Ethereum Foundation Blog

    Ethereum July 31, 2025

    Ethereum price prediction: ETH derivatives data shows weak momentum

    Ethereum July 31, 2025

    lean Ethereum | Ethereum Foundation Blog

    Ethereum July 31, 2025

    The Ethereum Foundation’s Next Chapter

    Ethereum July 31, 2025

    The Ethereum Foundation’s Vision | Ethereum Foundation Blog

    Ethereum July 30, 2025

    Ethereum Foundation’s Management and Board Structure

    Leave A Reply Cancel Reply

    Don't Miss
    Blockchain August 4, 2025

    FLUID price rallies as Fluid DEX dominates stablecoin swaps across Ethereum and L2s

    The DEX captured 55.5% of stable-stable swap volume on Ethereum, Base, Arbitrum, and Polygon. Dune…

    Where could Pepeto and XRP go if Bitcoin hits $21m?

    August 4, 2025

    Scammers using AI tools to steal crypto via deepfakes and wallet drainers

    August 4, 2025

    The Ether Machine crosses 345k ETH after $40m buy: what’s the endgame?

    August 4, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • YouTube
    • LinkedIn
    Our Picks

    FLUID price rallies as Fluid DEX dominates stablecoin swaps across Ethereum and L2s

    August 4, 2025

    Where could Pepeto and XRP go if Bitcoin hits $21m?

    August 4, 2025

    Scammers using AI tools to steal crypto via deepfakes and wallet drainers

    August 4, 2025

    The Ether Machine crosses 345k ETH after $40m buy: what’s the endgame?

    August 4, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Don't Miss
    Blockchain August 4, 2025

    FLUID price rallies as Fluid DEX dominates stablecoin swaps across Ethereum and L2s

    The DEX captured 55.5% of stable-stable swap volume on Ethereum, Base, Arbitrum, and Polygon. Dune…

    Where could Pepeto and XRP go if Bitcoin hits $21m?

    August 4, 2025

    Scammers using AI tools to steal crypto via deepfakes and wallet drainers

    August 4, 2025

    The Ether Machine crosses 345k ETH after $40m buy: what’s the endgame?

    August 4, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    About Us
    About Us

    ChainTechDaily.xyz delivers the latest updates and trends in the world of cryptocurrency. Stay informed with daily news, insights, and analysis tailored for crypto enthusiasts.

    Our Picks

    For Many Women, The Pain Of The Pandemic Led To Stronger Friendships

    January 15, 2020

    How A ‘Healthy’ Lifestyle Can Be Making You Tired

    January 15, 2020

    Fashion Influencers To Follow On Instagram In 2021

    January 15, 2020
    Lithosphere News Releases

    Imagen Network Uses Grok Intelligence to Improve Real Time Personalization in Social Apps

    August 4, 2025

    Imagen Network Brings RLUSD Payments Into Decentralized Applications to Improve Creator Accessibility

    July 31, 2025

    Imagen Network Expands Decentralized Infrastructure by Incorporating XRP for Fast Peer Transactions

    July 30, 2025

    Imagen Network Integrates Grok Framework to Enhance Feed Logic and Adaptive User Experience

    July 29, 2025
    X (Twitter) Instagram YouTube LinkedIn
    © 2025 Copyright

    Type above and press Enter to search. Press Esc to cancel.