CrediX Finance suffered a $4.5 million exploit after attackers gained admin accessCrediX Finance suffered a $4.5 million exploit after attackers gained admin access

CrediX Finance hacked for $4.5m via governance flaw

2025/08/04 20:54
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

CrediX Finance went offline after hackers used a multisig admin exploit to drain $4.5 million from the protocol.

Summary
  • CrediX Finance went offline after a $4.5M hack
  • Attackers used a vulnerability in its admin account
  • The protocol launched just one month ago

Security remains a key concern for DeFi projects, particularly those with centralized ownership and control. On Monday, August 4, less than a month after its launch, CrediX Finance went offline following a $4.5 million exploit.

https://twitter.com/SlowMist_Team/status/1952312873822396712

According to blockchain security firm SlowMist, the attackers gained access to the protocol’s multisig admin and bridge wallets six days before the incident. With this access, they acted as a bridge and minted collateral tokens.

These tokens were then used to borrow large amounts of crypto, quickly draining CrediX Finance’s liquidity pool. Security firm CertiK confirmed the protocol lost approximately $4.5 million. The attackers bridged the stolen funds from Sonic (S) to Ethereum (ETH).

How the CrediX Finance hack happened

CrediX Finance launched in July 2025 as a real-world asset lending protocol. It allowed borrowers to receive loans backed by off-chain income and collateral provided by DeFi lenders.

This incident is one of several recent DeFi-related exploits. According to CertiK, $153 million was lost to various crypto exploits and scams in July alone. Of this, exchange-related incidents accounted for $86.6 million, while code vulnerabilities caused $55.4 million in losses.

https://twitter.com/CertiKAlert/status/1951598860486234489

Despite the “decentralized” label, many DeFi protocols retain elements of centralization. Multisig admin wallets often have the ability to pause contracts, change protocol parameters, or mint new tokens.

For some projects, this is important in the early stage, as the protocol is developing. However, this also enables attackers to exploit these protocols if they are able to gain access to admin accounts.

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!