An Admin Role Sat Unused for Six Days, Then Printed $4.5M in Fake Collateral
Credix, a lending protocol on the Sonic chain, lost roughly $4.5 million on August 5, 2025, after an account holding compromised administrative and bridge permissions used them to mint collateral out of thin air and borrow real assets against it. Rather than a code exploit, the incident was a case of legitimate — but stolen or misused — access being turned against the protocol from the inside.
Timeline of disclosure

Credix confirmed a "security breach" publicly, saying further details would follow shortly. Four minutes later, the team took its website offline to block new deposits, telling users to interact with the contracts directly instead.
Roughly fifteen minutes after Credix's initial post, Cyvers reported that it had detected the activity, identifying a Tornado Cash-funded attacker who had already pulled around $2.64 million out of the protocol at that point. A follow-up Cyvers update revised the estimated total loss upward to $4.5 million, noting that most of the funds had already been bridged back to Ethereum before any monitoring firm could react.
Root cause: a six-day-old admin grant
According to SlowMist's analysis, the root cause traced back six days before the attack, when Credix's multisig granted the attacker's address both the Admin and Bridge roles via the protocol's ACLManager contract. The role-granting transaction is recorded on Sonicscan: 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae72e3b8e903334f35e.
PeckShield's writeup detailed the full scope of access involved — the compromised account held POOL_ADMIN, BRIDGE, ASSET_LISTING_ADMIN, EMERGENCY_ADMIN, and RISK_ADMIN privileges simultaneously. That account is identified on Sonicscan as 0xF321683831Be16eeD74dfA58b02a37483cEC662e.
The exploit mechanism
With the BRIDGE role in hand, the attacker minted acUSDC tokens with no backing collateral behind them, then used those fabricated tokens as loan collateral to borrow out roughly $4.5 million in genuine pool assets. Blockscope's breakdown and PeckShield's report both describe the same sequence: mint unbacked acUSDC directly into the pool via the bridge role, then borrow real assets against it. SlowMist similarly observed the attacker generating tokens from nothing and draining the liquidity pool to zero.
Credix's lending logic had no way to distinguish collateral created through the bridge's minting function from collateral backed by actual deposits, so loans against the fabricated acUSDC were approved as if they were legitimate. No private keys were leaked and no smart contract bug was involved — the loss stemmed entirely from privileged access being used maliciously.
Fund movement
The setup transaction granting the attacker's role six days ahead of the attack is the same one cited above: 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae72e3b8e903334f35e. The attacker's address was 0xF321683831Be16eeD74dfA58b02a37483cEC662e. The main exploit transaction is recorded at 0xe2501b4bb580b2ff6e59e68c0de50fd716bf2d096e1647c70f826bbd1352624d, with an additional related transaction at 0x713015811887d6c9886d08427a7415a7bcbbdca4b8c0e2dfa4970f0ab339d07f.
Blockscope confirmed the stolen funds were swapped into USDC and bridged over to Ethereum using deBridge. CertiK traced the proceeds across three initial Ethereum wallets:
- 0xea39a99090d7f8f7f8f9a88dd730c452dcd6dbba
- 0xc4662b3313333d18a3f49aee24972185114150b6
- 0xf321683831be16eed74dfa58b02a37483cec662e
Funds were later consolidated into a fourth wallet: 0x14C49c7C3992F3dD4bb001aAe5eaE52972eD7aC7. Blockscope subsequently set up monitoring on these addresses to track any further movement.

Response and recovery claims
Hours after acknowledging the breach, Credix stated that "all users funds will be recovered in full within 24-48 hours," without explaining the mechanism or reserves behind that guarantee. In the meantime, users remained locked out of deposits and were directed to withdraw directly from the smart contracts. Credix had also said it would share more details "soon," but as of the recovery announcement had not disclosed how the multisig came to grant admin and bridge roles to the attacker, or why those permissions went unreviewed for six days.
A few hours later, Credix announced it had reached a "successful parley with the exploiter, who agreed to return the funds within the next 24-48 hours" — reportedly in exchange for the attacker keeping an undisclosed portion of funds drawn from Credix's treasury. The team also said it would airdrop affected users their share of assets on the same timeline.
Outstanding questions
As of this report, it remained unclear exactly how the attacker's address originally obtained admin and bridge privileges on Credix's ACLManager six days before the exploit. The episode adds to a pattern in DeFi where the greatest risk to a protocol comes not from a code-level bug but from privileged accounts — multisig signers, admin roles, bridge operators — being compromised or misused, a category of failure that audits of the underlying smart contracts do not catch.
Get new scam files the moment we publish them — usually 2–3 emails a week.