Skip to content
← Back to newsCrediX Halts Operations After $4.5 Million DeFi Hack
Crime

CrediX Halts Operations After $4.5 Million DeFi Hack

By ToTo BugelmanNewcomer0 rep· 8/5/2025

CrediX Protocol Suffers $4.5 Million Hack, Halts Operations

The decentralized finance (DeFi) lending platform CrediX, built on the Sonic blockchain, has suspended its operations following a significant security breach that resulted in the loss of approximately $4.5 million in cryptocurrency. The platform's team took the website offline to prevent further deposits while investigating the incident.

 

CrediX_fi

 

Key Takeaways

  • CrediX, a DeFi lending platform on the Sonic blockchain, was hacked, losing around $4.5 million.

  • The platform's website was taken offline to stop new deposits.

  • An administrator account compromise is identified as the primary cause.

  • CrediX has pledged to reimburse affected users within 24-48 hours.

 

Details of the Attack

The security breach occurred on August 4th around 12:30 UTC+3. In a statement, CrediX alerted users to withdraw funds using smart contracts, as the website was temporarily disabled. The project's representatives assured users that all stolen assets would be compensated within a 24 to 48-hour timeframe.

 

Root Cause Identified

Security analysts from PeckShield identified the hack's root cause as a compromised administrator account. This account held multiple critical roles, including POOL_ADMIN, BRIDGE, ASSET_LISTING_ADMIN, EMERGENCY_ADMIN, and RISK_ADMIN. The attacker exploited the BRIDGE role to drain assets from the pools by minting uncollateralized acUSDC tokens.

 

PeckShield inc.

 

SlowMist further elaborated that the attacker gained administrative privileges and bridge rights to the CrediX multisig wallet six days prior to the incident via the ACLManager. This allowed the attacker to directly mint collateral tokens for themselves, leading to the depletion of the platform's pools.

 

SlowMist

 

Asset Movement and Industry Context

Data from CertiK indicates that the stolen cryptocurrency was moved from the Sonic network to the Ethereum network. At the time of reporting, the illicit funds were held across three different addresses. This incident highlights ongoing security challenges within the crypto industry, where rapid fund withdrawal after hacks remains a significant concern. In the first half of the year, hackers reportedly stole over $3.01 billion across 119 incidents.

 

CertiK Alert

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.