Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Exit scam? CrediX disappears after a $4.5M hack

Exit scam? CrediX disappears after a $4.5M hack

CryptopolitanCryptopolitan2025/08/08 23:55
By:By Hristina Vasileva

Share link:In this post: The CrediX team deleted the platform’s X account, sparking speculation that the recent hack was a rug pull. Other DeFi protocols on Sonic were also affected, and are now scrambling to contain the damage. Some of the stolen funds are already mixed through TornadoCash, though Sonic Labs and Stability DAO are still investigating the exploit.

The CrediX account on X has disappeared, with suggestions that the $4.5M recent hack may have been a rug pull. The lending protocol on Sonic chain suffered an attack with unlimited token minting, with up to $4.5M unauthorized assets created. 

The CrediX recent hack for a total of $4.5M is suspected to be an inside job and a form of rug pull. The relatively minor project on the Sonic chain was exploited on August 4, as on-chain researchers noted a $2.64M flash loan and a total of $4.5M in unauthorized wrapped USDC. 

As Cryptopolitan reported , the initial theory for the hack was a flawed smart contract or another form of access to the minting function. However, the disappearance of the CrediX account on X sparked suggestions of a rug pull. The disappearance of the team suggested the private keys were not leaked or taken from a code repository, but may have been controlled by the team all along. 

The team may have disappeared as a way to avoid tackling a complex DeFi situation with contagion to other protocols. However, some of the bridged funds on Ethereum were already moved through TornadoCash, with the remaining funds still being watched for transfers.

CrediX team disappears after promising compensation in 24 hours

Initially, the CrediX team stated it would reimburse all funds lost, but while traders waited, the team disappeared. The team said there would be a repayment of all claims through smart contracts to compensate for the funds stolen from the Sonic-Ethereum bridge. 

See also Trump's nominee for CFTC lead Brian Quintenz in limbo as backers withdraw support

Rug pulls have been relatively rare during the 2024-2025 bull cycle, with the exception of meme tokens. In the DeFi space, most projects tried to prove reliability and robust reserves, even in the face of hacks. Protocols like Cetus DEX managed to recover some of their funds and relaunch . There are also more robust efforts to track down and lock funds where possible. 

Based on the unauthorized minted wrapped tokens, the team may still have access to the 4.5M USDC on Ethereum, with no mention of tagging the wallet or freezing. In this case, the value did not disappear, but is held entirely by the exploiters. 

CrediX contagion spreads to other protocols

The CrediX loss caused panic to spread to other protocols, despite indirect exposure. Trevee, formerly Rings Protocol, was affected due to holding some scUSD from CrediX. 

Trevee staked the scUSD to mint metaUSD. When the CrediX exploit happened, all liquidity providers disappeared, leading to over $1.8M unbacked metaUSD. Rings Protocol covered some of the unbacked tokens, but still suffered a loss by holding 737,427 scUSD.

The fallout of CrediX essentially generated additional bad debt in the Trevee protocol, affecting stkscUSD and veUSD holders. To prevent further contagion, Trevee stopped minting and redemptions for its stablecoins.

See also Over 1,000 crypto pyramid schemes found in Russia this year

Stability DAO vaults were also affected by the draining of liquidity from CrediX stablecoins. Stability’s Metavaults were affected, with an estimated up to 30% to 40% of funds exposed to CrediX. Stability is working with the Sonic team to resolve the situation, which may include the doxing of the CrediX team and raising the case with authorities. Metavaults are now closed and expected to reopen next week.

The exploit did not affect Sonic, which still holds around $467 million in total value locked. Beets, Aave, and Silo Finance remain the top lending protocols, with around $400M in total value locked.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!