CrediX DeFi Protocol Exploited for $4.5M via Admin Privilege Abuse
DeFi lending protocol CrediX suffered a $4.5 million breach after attackers compromised administrative controls, minting unbacked collateral tokens through bridge privileges. The hacker Leveraged Tornado Cash-funded addresses to bridge assets to Sonic network before exploiting privileged roles to drain liquidity pools.
Security firms SlowMist and PeckShield traced the attack to address 0xF321***662e, which held POOL_ADMIN, BRIDGE, and EMERGENCY_ADMIN privileges. The exploit mirrors July 2024's $234 million WazirX breach, both demonstrating how compromised administrative access bypasses conventional security measures.
The attack remained undetected for six days as the hacker borrowed against artificially minted acUSDC tokens, ultimately extracting $2.64 million from lending pools. This incident underscores persistent vulnerabilities in DeFi privilege management systems.