• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
Subscribe To Our Newsletter
Home » Cryptocurrency

$4.5M CrediX Hack Underscores DeFi’s Multisig Weakness

Updated on: August 4, 2025
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
Dreamcash Secures Tether Backing for USDT0 Stock Perpetual Trading
Kalshi Targets 9 Billion Sports Insurance Market With New Deal
South Korea Police Lose 22 Bitcoin Seized in 2021 Case
Credix Defi Hacked
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

CrediX Finance lost $4.5 million in a devastating exploit just weeks after launch, highlighting urgent vulnerabilities in DeFi multisig wallet systems.

Key Takeaways

  • 1CrediX Finance was hacked for $4.5 million due to compromised admin and bridge access.
  • 2The attacker exploited governance flaws to mint fake collateral tokens and borrow funds.
  • 3Security firms link the breach to a broader trend of DeFi multisig wallet failures in 2025.
  • 4Experts are calling for AI-based real-time security monitoring to prevent future incidents.

What Happened?

CrediX Finance, a real-world asset lending protocol launched in July 2025, suffered a $4.5 million exploit on August 4. The attackers gained admin privileges days before the attack and minted fake collateral tokens, using them to drain the protocol’s liquidity pool. The hack has intensified scrutiny on the use of multisig wallets, which have become a key vulnerability in DeFi security this year.

🚨SlowMist TI Alert🚨

MistEye detected that @CrediX_fi has been exploited.

The CrediX Multisig Wallet, 6 days ago, added an attacker as both Admin and Bridge via ACLManager.https://t.co/E6tbBEI76M

This enabled the attacker, acting in the Bridge role, to directly mint… https://t.co/GiXswzNZqS pic.twitter.com/jJjYR1eyET

,SlowMist (@SlowMist_Team) August 4, 2025

CrediX Finance Targeted Just Weeks After Launch

CrediX Finance had only been live for about a month before the exploit occurred. The platform allowed users to borrow crypto loans against off-chain income and collateral, aiming to bridge real-world assets with decentralized finance. Unfortunately, the early-stage protocol retained centralized control mechanisms, including multisig admin wallets with bridge rights.

According to blockchain security firm SlowMist, the attacker was assigned Admin and Bridge roles via the protocol’s ACLManager six days before the hack. With these roles, the hacker minted collateral tokens through the CrediX Pool, borrowed $2.64 million, and eventually drained a total of $4.5 million from the platform.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Attacker Bridged Funds to Ethereum

Blockchain security platforms including CertiK and Cyvers Alerts traced the exploit across networks. The attacker initially funded a wallet through Tornado Cash on Ethereum, then bridged those funds to Sonic, where the CrediX Pool was hosted.

#CertiKInsight 🚨@CrediX_fi was exploited for ~$4.5M. All the funds were bridged from Sonic to Ethereum network.

Currently, the stolen funds are still in the attacker’s wallets.https://t.co/3s2sgA2QOehttps://t.co/yqDM4TETDUhttps://t.co/mN3kchx933

,CertiK Alert (@CertiKAlert) August 4, 2025

Once the pool was compromised, the hacker transferred the stolen assets back to Ethereum, effectively laundering the funds across chains. CertiK confirmed the timeline and amount lost, while CrediX promptly took its website offline to prevent further damage.

Multisig Wallets: The Achilles’ Heel of DeFi?

The CrediX incident is not isolated. According to Hacken, a security firm tracking crypto thefts, $3.1 billion has already been lost in DeFi exploits in 2025, with the majority tied to multisig wallet failures. These wallets, intended to add layers of transaction approval, have instead become a major security weak point.

Common attack vectors include:

  • Social engineering of multisig signers
  • Fake interfaces to trick users into approvals
  • Misconfigured access rights and admin privileges

The largest breach so far this year remains the $14.5 billion LuBian Mining Pool Scam, which was unearthed after five years.

Security Firms Call for AI Monitoring

In response to this growing threat, Hacken recommends abandoning one-time security audits in favor of real-time, AI-driven security monitoring. These tools can track multisig activity and alert teams to suspicious behavior immediately.

According to Hacken’s data:

  • Over 80% of DeFi losses in 2025 stemmed from access control failures
  • Improved signer education and interface security are essential
  • Automated rule-based protections should be standard practice

So far, CrediX has said it plans to recover the stolen funds within 24 to 48 hours, though no further updates have been made public.

All users funds will be recovered in full within 24-48 hours

,CrediX (@CrediX_fi) August 4, 2025

CoinLaw’s Takeaway

To be honest, this attack on CrediX feels like yet another red flag for DeFi. How many times do we have to watch millions vanish before platforms take admin and access control seriously? If you’re running a DeFi protocol and still relying on loosely managed multisig setups, you’re not innovating. You’re inviting disaster. It is no longer enough to say you’re “decentralized” if a single bad configuration can wipe out millions. I strongly believe the future of DeFi security lies in real-time, AI-powered monitoring, not delayed audits or patched fixes. Let’s hope the industry starts listening.

Read more about Blockchain

Blockchain

Blockchain is a decentralized digital ledger that records transactions across multiple computers, making the data transparent, secure, and tamper-resistant. It powers cryptocurrencies but is also used in supply chains, finance, and many other industries.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Related Posts

X Plans In App Stock and Crypto Trading With Smart Cashtags Launch
Fintech

X Plans In App Stock and Crypto Trading With Smart Cashtags Launch

Dreamcash Secures Tether Backing for USDT0 Stock Perpetual Trading
Investments

Dreamcash Secures Tether Backing for USDT0 Stock Perpetual Trading

Kalshi Targets 9 Billion Sports Insurance Market With New Deal
Insurance

Kalshi Targets 9 Billion Sports Insurance Market With New Deal

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

South Korea Police Lose 22 Bitcoin Seized in 2021 Case
Mixin Network Hacker Sends 2,005 ETH to Tornado Cash
Binance Fired Investigators Who Flagged 1B Iran USDT Flows

Table of Contents

  • Key Takeaways
  • What Happened?
  • CrediX Finance Targeted Just Weeks After Launch
  • Attacker Bridged Funds to Ethereum
  • Multisig Wallets: The Achilles’ Heel of DeFi?
  • Security Firms Call for AI Monitoring
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Site Links

  • About CoinLaw
  • Newsletter
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Worth Checking

  • Debit Card Statistics
  • NFT Market Growth Statistics
  • Retail Investing Statistics
  • Credit Card Fraud Statistics
  • Most Expensive Crypto Scams
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Mawson Infra. Statistics
Mawson Infra. Statistics 2026: Market Edge
Digihost Statistics
Digihost Statistics 2026: Key Growth Data
Greenidge Generation Statistics
Greenidge Generation Statistics 2026: Energy Focus
Stronghold Digital Statistics
Stronghold Digital Statistics 2026: What’s Surging Now?
Argo Blockchain Statistics
Argo Blockchain Statistics 2026: BTC Mining on the Edge
Applied Digital Statistics
Applied Digital Statistics 2026: Secrets Behind the Surge
Payments
BHIM App Statistics
BHIM App Statistics 2026: Real Numbers, Big Impact
Amazon Pay Statistics
Amazon Pay Statistics 2026: Secrets Uncovered
WeChat Statistics
WeChat Statistics 2026: Mind-Blowing New Data
2Checkout Statistics
2Checkout Statistics 2026: Growth Secrets Unveiled
Debit Card Statistics
Debit Card Statistics 2026: Insights That Matter Now
American Express Statistics
American Express Statistics 2026: Inside the Financial Surge Now
Finance
GitHub Statistics
GitHub Statistics 2026: What You Must Know Now
Financial Literacy Statistics
Financial Literacy Statistics 2026: What Most Get Wrong Now
Decentralized Finance Defi Market Statistics
Decentralized Finance (DeFi) Market Statistics 2026: Must-Know Insights Now
Quantum Cryptography in Finance Statistics
Quantum Cryptography in Finance Statistics 2026: Security or Chaos?
Global Household Savings Statistics
Global Household Savings Statistics 2026: See How Your Country Ranks
Gen Alpha Financial Behavior Statistics
Gen Alpha Financial Behavior Statistics 2026: What Brands Must Know Now
Banking
Banking Statistics
Banking Statistics 2026: What You Must Know Now
ATM Statistics
ATM Statistics 2026: Insights You Must See Now
Neobank Industry Statistics
Neobank Industry Statistics 2026: Tap Into Explosive Revenue Secrets
UBS Statistics
UBS Statistics 2026: New Data, Big Surprises Ahead
Deutsche Bank Statistics
Deutsche Bank Statistics 2026: Hidden Trends Exposed Now
Digital Banking Statistics
Digital Banking Statistics 2026: What’s Surging Now
Insurance
Auto Insurance Industry Statistics
Auto Insurance Industry Statistics 2026: Growth Secrets
AI in Insurance Industry Statistics
AI in Insurance Industry Statistics 2026: Shocking Growth Insights
AI in Insurance Claims Statistics
AI in Insurance Claims Statistics 2026: How AI Wins Big
US Insurance Industry Statistics
US Insurance Industry Statistics 2026: What’s Surging Now
Property and Casualty Insurance Statistics
Property and Casualty Insurance Statistics 2026: Shocking Trends You Must See Now
Insurance Industry Statistics
Insurance Industry Statistics 2026: Trends That Will Shock You
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
South Korea Police Lose 22 Bitcoin Seized In 2021 Case
South Korea Police Lose 22 Bitcoin Seized in 2021 Case
Mixin Network Hacker Sends 2 005 Eth To Tornado Cash
Mixin Network Hacker Sends 2,005 ETH to Tornado Cash
Binance Fired Investigators Who Flagged 1b Iran Usdt Flows
Binance Fired Investigators Who Flagged 1B Iran USDT Flows
Brazil Plans To Buy 1 Million Bitcoin For National Reserve
Brazil Plans to Buy 1 Million Bitcoin for National Reserve
Taurus Partners With Blockdaemon On Crypto Staking
Taurus Partners with Blockdaemon on Crypto Staking
Coinbase Posts Q4 2025 Losses
Coinbase Reports $667M Loss Amid Crypto Market Slump
Investments
Dreamcash Secures Tether Backing For Usdt0 Stock Perpetual Trading
Dreamcash Secures Tether Backing for USDT0 Stock Perpetual Trading
Cango Raises 75m To Expand Bitcoin Mining And Ai Compute
Cango Raises 75M to Expand Bitcoin Mining and AI Compute
Tether Invests In Layerzero Labs
Tether Invests in LayerZero to Scale USDt0 and Agentic Finance
Galaxy Digital Approves 200m Stock Buyback
Galaxy Digital Approves $200M Stock Buyback Despite Recent Losses
Tether Invests 100m Usd In Anchorage Digital
Tether Backs Anchorage Digital With $100M Equity
Terawulf Expands Ai And Hpc Data Center
TeraWulf Expands Power Portfolio and Joins AI Data Center Race
Compliance
Hong Kong To Issue Stablecoin Licenses Amid China Crypto Ban
Hong Kong Advances Stablecoin Plans Despite China Ban
Polymarket Sues Massachusetts Over Sports Prediction Ban
Polymarket Sues Massachusetts Over Sports Prediction Ban
China Bans Crypto Issuance By Domestic Firms Overseas
China Bans Crypto Issuance by Domestic Firms Overseas
Wlfi Faces House Probe Over 500m Uae Royal Investment
WLFI Faces House Probe Over $500M UAE Royal Investment
South Korea Probes Zksync Price Surge On Upbit
South Korea Probes ZKsync Price Surge on Upbit
Nevada Sues Coinbase Over Unlicensed Predictions Market
Nevada Sues Coinbase Over Unlicensed Prediction Markets
Fintech
X Plans In App Stock And Crypto Trading
X Plans In App Stock and Crypto Trading With Smart Cashtags Launch
Uk Treasury Taps Hsbc For Bond Tokenization
UK Treasury Taps HSBC for Blockchain Based Sovereign Bond Pilot
Eu Moves Forward With Ecb Digital Euro Proposal
EU Moves Forward With ECB Digital Euro Proposal
Draftkings Adds Nfl Nba Player Props With Crypto Com Deal
DraftKings Adds NFL, NBA Player Props With Crypto.com Deal
Kalshi Expands Insider Trading Surveilance With Tools
Kalshi Expands Surveillance to Fight Insider Trading
Kalshi And Polymarket Open Temporary Free Grocery Stores In Nyc
Free Groceries in NYC as Kalshi, Polymarket Compete
Finance
Bitcoin Crash Hits Galaxy Digital Hard With 482m Q4 Loss
Bitcoin Crash Hits Galaxy Digital Hard with $482M Q4 Loss
Ripple Cleared For Eu Expansion With Full Luxembourg Emi License
Ripple Cleared for EU Expansion with Full Luxembourg EMI License
Chainlink Etf By Bitwise Goes Live On Nyse
Chainlink Gets a Wall Street Gateway as Bitwise Spot ETF Hits NYSE
Pharos Foundation Live For Open Finance
Pharos Foundation Debuts to Drive Institutional Adoption of Open Finance
Gemini Posts Lackluster Q3 Results After Ipo
Gemini’s First Post-IPO Report Shows Revenue Growth but Mounting Losses
Coinbase Posts Profit In Q3 Results
Coinbase Posts $433M Profit as Trading and Subscriptions Surge in Q3
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.