CrediX Protocol Suffers $4.5 Million Hack, Halts Operations
The decentralized finance (DeFi) lending platform CrediX, built on the Sonic blockchain, has suspended its operations following a significant security breach that resulted in the loss of approximately $4.5 million in cryptocurrency. The platform's team took the website offline to prevent further deposits while investigating the incident.
Key Takeaways
-
CrediX, a DeFi lending platform on the Sonic blockchain, was hacked, losing around $4.5 million.
-
The platform's website was taken offline to stop new deposits.
-
An administrator account compromise is identified as the primary cause.
-
CrediX has pledged to reimburse affected users within 24-48 hours.
Details of the Attack
The security breach occurred on August 4th around 12:30 UTC+3. In a statement, CrediX alerted users to withdraw funds using smart contracts, as the website was temporarily disabled. The project's representatives assured users that all stolen assets would be compensated within a 24 to 48-hour timeframe.
Root Cause Identified
Security analysts from PeckShield identified the hack's root cause as a compromised administrator account. This account held multiple critical roles, including POOL_ADMIN, BRIDGE, ASSET_LISTING_ADMIN, EMERGENCY_ADMIN, and RISK_ADMIN. The attacker exploited the BRIDGE role to drain assets from the pools by minting uncollateralized acUSDC tokens.
SlowMist further elaborated that the attacker gained administrative privileges and bridge rights to the CrediX multisig wallet six days prior to the incident via the ACLManager. This allowed the attacker to directly mint collateral tokens for themselves, leading to the depletion of the platform's pools.
Asset Movement and Industry Context
Data from CertiK indicates that the stolen cryptocurrency was moved from the Sonic network to the Ethereum network. At the time of reporting, the illicit funds were held across three different addresses. This incident highlights ongoing security challenges within the crypto industry, where rapid fund withdrawal after hacks remains a significant concern. In the first half of the year, hackers reportedly stole over $3.01 billion across 119 incidents.
Sources
-
Протокол CrediX остановил работу после взлома на $4,5 млн, ForkLog.
-
DeFi Protocol CrediX Taken Offline After $4.5M Exploit, CoinDesk
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.