- Hackers have breached the DeFi protocol CrediX, resulting in a $4.5 million theft.
- The stolen funds were transferred from Sonic to Ethereum and distributed across three wallets, as confirmed by CertiK.
- CrediX promises to return all funds to users within 48 hours following the attack.
- This incident highlights the increasing vulnerabilities in DeFi infrastructure, particularly concerning multi-signature wallets.
DeFi Protocol CrediX Breached for $4.5 Million
In a startling turn of events on August 4, 2025, hackers successfully targeted the DeFi protocol CrediX Finance, leading to a significant loss of approximately $4.5 million. The breach occurred less than a month after the project’s launch on the Sonic platform.
Cybersecurity firm CertiK has reported that these stolen assets were withdrawn from the Sonic network into Ethereum and subsequently spread across three different wallets. The exact method of attack remains unknown as investigations continue.
Immediate Response and User Assurance
Following the attack’s discovery, CrediX swiftly disabled their website to prevent users from conducting new transactions. To reassure their community, project representatives promised via social media platform X (formerly known as Twitter) that all user funds would be returned within 24-48 hours.
The situation was further clarified by analysts at SlowMist who noted that days before the breach, an attacker gained access to multi-signature controls and bridge management. They exploited these permissions to create collateral and secure large loans, extracting substantial liquidity from the pool.
Implications for DeFi Security
This breach underscores an emerging trend in 2025: multi-signature wallet attacks have become a major threat vector within decentralized finance (DeFi). According to CertiK’s observations, losses from such incidents exceeded $3.1 billion in just the first half of this year alone, highlighting growing vulnerabilities in crypto infrastructure.
Despite being a new product on Sonic’s platform for only several weeks, CrediX itself has been operational since 2021 with a focus on real-world asset-backed lending (RWA). Previously securing a $60 million credit line demonstrates its foundational strength despite recent challenges.
A Broader Perspective on Crypto Security
This incident serves as a stark reminder of ongoing security challenges facing the crypto industry today. With losses mounting due to sophisticated cyber threats targeting vulnerable protocols like CrediX Finance—and previous cases such as Arkham Intelligence revealing record-breaking Bitcoin thefts—there is an urgent call for improved security measures across all digital finance platforms.
As we witness advancements in blockchain technology and its applications expand globally beyond borders into everyday transactions worldwide—it becomes increasingly crucial that stakeholders prioritize robust cybersecurity strategies while continuing innovation efforts toward building safer ecosystems where trust can flourish among users engaging with decentralized finance solutions daily.
