• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
Subscribe To Our Newsletter
Home » Cryptocurrency

$4.5M CrediX Hack Underscores DeFi’s Multisig Weakness

Published on: August 4, 2025
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor • 1,366 Articles
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
MARA Sells Bitcoin to Cut $1B Debt, Stock Jumps 10%
Coinbase Launches Crypto Backed Mortgages With Better
Anchorage Digital Adds TRON Support for Institutional Investors
Credix Defi Hacked
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

CrediX Finance lost $4.5 million in a devastating exploit just weeks after launch, highlighting urgent vulnerabilities in DeFi multisig wallet systems.

Key Takeaways

  • 1CrediX Finance was hacked for $4.5 million due to compromised admin and bridge access.
  • 2The attacker exploited governance flaws to mint fake collateral tokens and borrow funds.
  • 3Security firms link the breach to a broader trend of DeFi multisig wallet failures in 2025.
  • 4Experts are calling for AI-based real-time security monitoring to prevent future incidents.

What Happened?

CrediX Finance, a real-world asset lending protocol launched in July 2025, suffered a $4.5 million exploit on August 4. The attackers gained admin privileges days before the attack and minted fake collateral tokens, using them to drain the protocol’s liquidity pool. The hack has intensified scrutiny on the use of multisig wallets, which have become a key vulnerability in DeFi security this year.

🚨SlowMist TI Alert🚨

MistEye detected that @CrediX_fi has been exploited.

The CrediX Multisig Wallet, 6 days ago, added an attacker as both Admin and Bridge via ACLManager.https://t.co/E6tbBEI76M

This enabled the attacker, acting in the Bridge role, to directly mint… https://t.co/GiXswzNZqS pic.twitter.com/jJjYR1eyET

,SlowMist (@SlowMist_Team) August 4, 2025

CrediX Finance Targeted Just Weeks After Launch

CrediX Finance had only been live for about a month before the exploit occurred. The platform allowed users to borrow crypto loans against off-chain income and collateral, aiming to bridge real-world assets with decentralized finance. Unfortunately, the early-stage protocol retained centralized control mechanisms, including multisig admin wallets with bridge rights.

According to blockchain security firm SlowMist, the attacker was assigned Admin and Bridge roles via the protocol’s ACLManager six days before the hack. With these roles, the hacker minted collateral tokens through the CrediX Pool, borrowed $2.64 million, and eventually drained a total of $4.5 million from the platform.

Attacker Bridged Funds to Ethereum

Blockchain security platforms including CertiK and Cyvers Alerts traced the exploit across networks. The attacker initially funded a wallet through Tornado Cash on Ethereum, then bridged those funds to Sonic, where the CrediX Pool was hosted.

#CertiKInsight 🚨@CrediX_fi was exploited for ~$4.5M. All the funds were bridged from Sonic to Ethereum network.

Currently, the stolen funds are still in the attacker’s wallets.https://t.co/3s2sgA2QOehttps://t.co/yqDM4TETDUhttps://t.co/mN3kchx933

,CertiK Alert (@CertiKAlert) August 4, 2025

Once the pool was compromised, the hacker transferred the stolen assets back to Ethereum, effectively laundering the funds across chains. CertiK confirmed the timeline and amount lost, while CrediX promptly took its website offline to prevent further damage.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Multisig Wallets: The Achilles’ Heel of DeFi?

The CrediX incident is not isolated. According to Hacken, a security firm tracking crypto thefts, $3.1 billion has already been lost in DeFi exploits in 2025, with the majority tied to multisig wallet failures. These wallets, intended to add layers of transaction approval, have instead become a major security weak point.

Common attack vectors include:

  • Social engineering of multisig signers
  • Fake interfaces to trick users into approvals
  • Misconfigured access rights and admin privileges

The largest breach so far this year remains the $14.5 billion LuBian Mining Pool Scam, which was unearthed after five years.

Security Firms Call for AI Monitoring

In response to this growing threat, Hacken recommends abandoning one-time security audits in favor of real-time, AI-driven security monitoring. These tools can track multisig activity and alert teams to suspicious behavior immediately.

According to Hacken’s data:

  • Over 80% of DeFi losses in 2025 stemmed from access control failures
  • Improved signer education and interface security are essential
  • Automated rule-based protections should be standard practice

So far, CrediX has said it plans to recover the stolen funds within 24 to 48 hours, though no further updates have been made public.

All users funds will be recovered in full within 24-48 hours

,CrediX (@CrediX_fi) August 4, 2025

CoinLaw’s Takeaway

To be honest, this attack on CrediX feels like yet another red flag for DeFi. How many times do we have to watch millions vanish before platforms take admin and access control seriously? If you’re running a DeFi protocol and still relying on loosely managed multisig setups, you’re not innovating. You’re inviting disaster. It is no longer enough to say you’re “decentralized” if a single bad configuration can wipe out millions. I strongly believe the future of DeFi security lies in real-time, AI-powered monitoring, not delayed audits or patched fixes. Let’s hope the industry starts listening.

CoinLaw follows strict Publishing Principles to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Related Posts

Uniswap V4-Based Bunni DEX Shuts Down After Devastating Exploit
Cryptocurrency

Uniswap V4-Based Bunni DEX Shuts Down After Devastating Exploit

Malware in Crypto Smart Contracts 2026: Critical Mistakes to Avoid
Cryptocurrency

Malware in Crypto Smart Contracts 2026: Critical Mistakes to Avoid

Most Expensive Crypto Exchange Hacks: How Billions Were Lost and Lessons Learned
Cryptocurrency

Most Expensive Crypto Exchange Hacks: How Billions Were Lost and Lessons Learned

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

$4.5M Hack Reversed: CrediX Strikes Private Deal With Exploiter
CoinDCX Loses $44 Million in Hot Wallet Hack, Customer Funds Safe
Hacker Launders $19M in ETH After $27M Multisig Wallet Heist

Table of Contents

  • Key Takeaways
  • What Happened?
  • CrediX Finance Targeted Just Weeks After Launch
  • Attacker Bridged Funds to Ethereum
  • Multisig Wallets: The Achilles’ Heel of DeFi?
  • Security Firms Call for AI Monitoring
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Site Links

  • About CoinLaw
  • Newsletter
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Worth Checking

  • Debit Card Statistics
  • NFT Market Growth Statistics
  • Retail Investing Statistics
  • Credit Card Fraud Statistics
  • Most Expensive Crypto Scams
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Crypto Exchange Hacks and Security Statistics 2026: Cyber Risk Trends
Crypto Exchange Hacks and Security Statistics 2026: Cyber Risk Trends
Blockchain in Energy Trading Statistics 2026: How Blockchain is Transforming the Market
Blockchain in Energy Trading Statistics 2026: How Blockchain is Transforming the Market
Algorithmic Stablecoins Statistics 2026: Adoption, Performance, and Challenge
Algorithmic Stablecoins Statistics 2026: Adoption, Performance, and Challenge
Metaplanet Statistics 2026: Explosive BTC Growth
Metaplanet Statistics 2026: Explosive BTC Growth
INX Digital Statistics 2026: Powerful Market Insights
INX Digital Statistics 2026: Powerful Market Insights
Transak Statistics 2026: Key Metrics You Must See Now
Transak Statistics 2026: Key Metrics You Must See Now
Payments
Worldpay Statistics 2026: Massive Payment Growth
Worldpay Statistics 2026: Massive Payment Growth
Payment Processing Solutions Statistics 2026: Fintech Growth
Payment Processing Solutions Statistics 2026: Fintech Growth
Online Payment Statistics 2026: Explosive Growth
Online Payment Statistics 2026: Explosive Growth
Money Transfer Industry Statistics 2026: Global Surge Now
Money Transfer Industry Statistics 2026: Global Surge Now
Mobile Wallet Industry Statistics 2026: User Growth Trends
Mobile Wallet Industry Statistics 2026: User Growth Trends
Merchant Services Industry Statistics 2026: Innovations, Payments, and Security
Merchant Services Industry Statistics 2026: Innovations, Payments, and Security
Finance
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
US Corporate Bond Industry Statistics 2026: Hidden Trends Now
US Corporate Bond Industry Statistics 2026: Hidden Trends Now
Personal Finance App Industry Statistics 2026: Smart Money Apps Now
Personal Finance App Industry Statistics 2026: Smart Money Apps Now
Inflation Statistics 2026: Latest Trends, Comparisons, and Economic Impacts
Inflation Statistics 2026: Latest Trends, Comparisons, and Economic Impacts
Banking
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Wells Fargo Statistics 2026: Growth, Revenue Insights
Wells Fargo Statistics 2026: Growth, Revenue Insights
Bank of America Statistics 2026: Latest Key Numbers
Bank of America Statistics 2026: Latest Key Numbers
JPMorgan Chase Statistics 2026: Growth Insights
JPMorgan Chase Statistics 2026: Growth Insights
Online Banking Usage Statistics 2026: Shocking Growth
Online Banking Usage Statistics 2026: Shocking Growth
Digital Transformation in Banking Statistics 2026: Growth, Challenges, and Opportunities
Digital Transformation in Banking Statistics 2026: Growth, Challenges, and Opportunities
Insurance
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Travel Insurance Industry Statistics 2026: Hidden Trends Now
Travel Insurance Industry Statistics 2026: Hidden Trends Now
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
MARA Sells Bitcoin to Cut $1B Debt, Stock Jumps 10%
MARA Sells Bitcoin to Cut $1B Debt, Stock Jumps 10%
Anchorage Digital Adds TRON Support for Institutional Investors
Anchorage Digital Adds TRON Support for Institutional Investors
Canton and LayerZero Enable Cross-Chain Tokenized Assets
Canton and LayerZero Enable Cross-Chain Tokenized Assets
Brazil Targets Organized Crime with New Crypto Seizure Law
Brazil Targets Organized Crime with New Crypto Seizure Law
USDT0 Goes Live on Tempo to Improve Stablecoin Liquidity
USDT0 Goes Live on Tempo to Improve Stablecoin Liquidity
BitGo and ZKsync Bring Banks Onchain With Tokenized Deposits
BitGo and ZKsync Bring Banks Onchain With Tokenized Deposits
Investments
Robinhood Announces $1.5B Buyback Amid Stock Decline
Robinhood Announces $1.5B Buyback Amid Stock Decline
Ledger Completes $50M Sale as IPO Plans Stay on Hold
Ledger Completes $50M Sale as IPO Plans Stay on Hold
BitGo Partners With Susquehanna to Launch Prediction Markets
BitGo Partners With Susquehanna to Launch Prediction Markets
Michael Saylor’s Strategy Eyes $42B Bitcoin Buy Plan
Michael Saylor’s Strategy Eyes $42B Bitcoin Buy Plan
Eightco Expands OpenAI Investment to $90M Amid AI Push
Eightco Expands OpenAI Investment to $90M Amid AI Push
XRP Treasury Firm Evernorth Files S-4 for $1B Nasdaq Debut
XRP Treasury Firm Evernorth Files S-4 for $1B Nasdaq Debut
Compliance
UK Bans Crypto Donations, Caps Overseas Political Funding
UK Bans Crypto Donations, Caps Overseas Political Funding
CFTC Unveils Task Force for Crypto and AI Rules
CFTC Unveils Task Force for Crypto and AI Rules
Australia Moves Toward New Crypto Regulation Framework
Australia Moves Toward New Crypto Regulation Framework
SEC and CFTC Sign MoU to Coordinate US Crypto Regulation
SEC and CFTC Sign MoU to Coordinate US Crypto Regulation
Bithumb Faces Six Month Suspension Over AML Violations
Bithumb Faces Six Month Suspension Over AML Violations
Dubai Regulator Orders KuCoin to Halt Crypto Services
Dubai Regulator Orders KuCoin to Halt Crypto Services
Fintech
Tether Brings XAU₮ to BNB Chain Amid Gold Demand Surge
Tether Brings XAU₮ to BNB Chain Amid Gold Demand Surge
Circle Partners With Sasai to Expand USDC Payments in Africa
Circle Partners With Sasai to Expand USDC Payments in Africa
Mastercard and Western Union Join Solana Platform
Mastercard and Western Union Join Solana Platform
TRON Expands AI Fund to $1 Billion for Agent Economy
TRON Expands AI Fund to $1 Billion for Agent Economy
MoonPay Launches Open Wallet Standard for AI Agents
MoonPay Launches Open Wallet Standard for AI Agents
Playnance Launches Democratic Gaming Protocol with GCOIN
Playnance Launches Democratic Gaming Protocol with GCOIN
Finance
21Shares Rolls Out Strategy Yield ETP on Euronext Amsterdam
21Shares Rolls Out Strategy Yield ETP on Euronext Amsterdam
Yahoo Finance Adds Coinbase Trading as Stock Rollout Expands
Yahoo Finance Adds Coinbase Trading as Stock Rollout Expands
Bitcoin Crash Hits Galaxy Digital Hard with $482M Q4 Loss
Bitcoin Crash Hits Galaxy Digital Hard with $482M Q4 Loss
Ripple Cleared for EU Expansion with Full Luxembourg EMI License
Ripple Cleared for EU Expansion with Full Luxembourg EMI License
Chainlink Gets a Wall Street Gateway as Bitwise Spot ETF Hits NYSE
Chainlink Gets a Wall Street Gateway as Bitwise Spot ETF Hits NYSE
Pharos Foundation Debuts to Drive Institutional Adoption of Open Finance
Pharos Foundation Debuts to Drive Institutional Adoption of Open Finance
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.