{"id":11457,"date":"2025-08-09T06:00:25","date_gmt":"2025-08-09T06:00:25","guid":{"rendered":"https:\/\/coinsrise.net\/blog\/exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit\/"},"modified":"2025-08-09T06:00:25","modified_gmt":"2025-08-09T06:00:25","slug":"exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit","status":"publish","type":"post","link":"https:\/\/coinsrise.net\/blog\/exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit\/","title":{"rendered":"Exit Scam? DeFi Protocol CrediX\u2019s Team Vanishes Following $4.5 Million Exploit"},"content":{"rendered":"<p style=\"font-weight: 400\">The team behind the DeFi protocol CrediX is suspected of an exit scam following a recent $4.5 million security breach. The team has reportedly \u201cvanished\u201d from the project\u2019s official channels despite promising refunds, leaving customers empty-handed.<\/p>\n<h2 style=\"font-weight: 400\">DeFi Protocol Suffers $4.5 Million Exploit<\/h2>\n<p style=\"font-weight: 400\">On Friday, security firm CertiK reported that the DeFi lender CrediX\u2019s team had disappeared following the platform\u2019s recent exploit, leaving its website offline since the August 4 incident and suddenly deleting the official X account.<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" class=\"size-large wp-image-801803\" src=\"https:\/\/www.newsbtc.com\/wp-content\/uploads\/2025\/08\/Gx0dipNXIAADrnF.png?w=601&#038;resize=601%2C641\" alt=\"DeFi\" width=\"601\" height=\"641\" loading=\"lazy\" \/><\/p>\n<p style=\"font-weight: 400\">For context, the Sonic-based DeFi lender suffered a security breach on Monday after a potential wallet compromise led to the theft of $4.5 million from the protocol\u2019s liquidity pool.<\/p>\n<p style=\"font-weight: 400\">Blockchain security firm PeckShield <a href=\"https:\/\/x.com\/peckshield\/status\/1952317721271488693\" target=\"_blank\" rel=\"noopener nofollow\">explained<\/a> that the alleged hack was due to a compromised admin account, which allowed the exploiter to abuse its BRIDGE role to mint unbacked acUSDC (Sonic USDC) tokens, borrow against them, and drain the pool, before bridging the assets from Sonic Network to Ethereum.<\/p>\n<p style=\"font-weight: 400\">Notably, SlowMist found that the CrediX multisig wallet added an attacker as an admin and bridge role via ACLManager six days before, which raised concerns among investors.<\/p>\n<p style=\"font-weight: 400\">The DeFi lender\u2019s team acknowledged the incident on X, stating that they had disabled the website to prevent users from depositing. Later, the team informed its community that it had allegedly \u201creached successful parley with the exploiter, who agreed to return the funds within the next 24-48 hours.\u201d<\/p>\n<p style=\"font-weight: 400\">According to the now-deleted post, <a href=\"https:\/\/t.me\/CrediXchat\/12609\" target=\"_blank\" rel=\"noopener nofollow\">posted<\/a> on CrediX\u2019s official Telegram account by a user, the attacker agreed to return the funds \u201cin return for money fully paid by the credix treasury.\u201d<\/p>\n<p style=\"font-weight: 400\">The team affirmed that they would airdrop the funds to the affected users\u2019 addresses in \u201cthe respective timeframe.\u201d<\/p>\n<h2 style=\"font-weight: 400\">CrediX Goes Dark<\/h2>\n<p style=\"font-weight: 400\">The following day, the team addressed the exploit on Telegram, stating, \u201cWe are truly sorry for this devastating incident and the impact it may have on our community,\u201d and affirmed that they would keep users updated on the next steps before disappearing and deactivating the official X account.<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" class=\"size-large wp-image-801802\" src=\"https:\/\/www.newsbtc.com\/wp-content\/uploads\/2025\/08\/Captura-de-Pantalla-2025-08-08-a-las-5.24.41-p.-m.png?w=483&#038;resize=483%2C429\" alt=\"DeFi\" width=\"483\" height=\"429\" loading=\"lazy\" \/><\/p>\n<p style=\"font-weight: 400\">On Thursday, the Sonic-based Stability DAO <a href=\"https:\/\/x.com\/bsc_tomas\/status\/1953513770606899484\" target=\"_blank\" rel=\"noopener nofollow\">confirmed<\/a> on its Discord server that CrediX had \u201cgone dark and disappeared,\u201d directly affecting the protocol\u2019s users. The exploit affected Stability DAO\u2019s Metavaults as the project had recently integrated with CrediX.<\/p>\n<p style=\"font-weight: 400\">In the message, the protocol announced that all the affected teams, including Sonic Labs, Euler, Beets, and Rines Protocol (Trevee), were in communication and actively working on \u201cfiling a formal legal report with the authorities in hopes of recovering lost funds.\u201d<\/p>\n<p style=\"font-weight: 400\">Additionally, they have obtained information on two of the DeFi lender\u2019s members, which would be added to the report alongside the rest of the evidence.<\/p>\n<p style=\"font-weight: 400\">\u201cA full incident report will be shared with the community soon, outlining everything that happened and what steps are being taken,\u201d the message vowed.<\/p>\n<p style=\"font-weight: 400\">This incident follows the alarming trend that has been developing this year. As reported by NewsBTC, crypto theft has surged this year, reaching a total loss of $2.7 billion in the first half of 2025.<\/p>\n<p style=\"font-weight: 400\">By the end of June, more value had been stolen year-to-date (YTD) than during the same period in 2022, suggesting that theft from crypto services and DeFi projects could potentially hit $4.3 billion by year\u2019s end.<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" class=\"size-large wp-image-801801\" src=\"https:\/\/www.newsbtc.com\/wp-content\/uploads\/2025\/08\/ETHUSDT_2025-08-08_14-21-21.png?w=860&#038;resize=860%2C495\" alt=\"DeFi, ethereum, eth, ethusdt\" width=\"860\" height=\"495\" loading=\"lazy\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The team behind the DeFi protocol CrediX is suspected of an exit scam following a recent $4.5 million security breach. The team has reportedly \u201cvanished\u201d from the project\u2019s official channels despite promising refunds, leaving customers empty-handed. DeFi Protocol Suffers $4.5 Million Exploit On Friday, security firm CertiK reported that the DeFi lender CrediX\u2019s team had&hellip;<\/p>\n","protected":false},"author":1,"featured_media":11458,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[4565,1984,1985,3264,17,4566,1797,43,45,47,4403,2386,4567,4568],"class_list":["post-11457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency-market-news","tag-credix","tag-crypto-exploit","tag-crypto-hack","tag-crypto-theft","tag-cryptocurrency-market-news","tag-defi-lender","tag-defi-protocol","tag-eth","tag-ethereum","tag-ethusdt","tag-exit-scam","tag-sonic-labs","tag-sonic-network","tag-stability-dao"],"_links":{"self":[{"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/posts\/11457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/comments?post=11457"}],"version-history":[{"count":0,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/posts\/11457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/media\/11458"}],"wp:attachment":[{"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/media?parent=11457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/categories?post=11457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinsrise.net\/blog\/wp-json\/wp\/v2\/tags?post=11457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}