13 Million $ Leak from Abracadabra: Fresh Attack on DeFi Sphere

26 March 2025 2 minutes Author: Newsman

Decentralized credit platform Abracadabra.money is under attack again: this is the second hack in a year, during which hackers withdrew cryptocurrencies for more than 6,000 ETH, which at the time of the attack corresponded to more than $ 13 million

Representatives of the project confirmed the fact of the hack on social networks. According to preliminary data, the attackers used a vulnerability in one of the credit systems, which is associated with the “cauldrons” – a liquidity pool operating with GMX. At the same time, GMX emphasized that its smart contracts remain protected.

After the Zeroshadow security team reported suspicious activity, Abracadabra promptly suspended all borrowing functions and launched an internal investigation. According to their statements, user security was not affected. In the meantime, the hacker transferred tokens from Arbitrum to the Ethereum network and placed them in three separate wallets. The project offered him a 20% reward to get some of the funds back.

This is the second attack on Abracadabra in the last 14 months: in January 2024, the platform lost $6.5 million due to another vulnerability in smart contracts. Abracadabra operates on the basis of the inflationary stablecoin Magic Internet Money (MIM), which users create using collateral in the form of interest-bearing tokens.

Despite various protection systems, DeFi projects remain vulnerable to well-planned attacks. Abracadabra, although it reacted quickly, lost not only funds, but also trust. This incident once again calls into question security in decentralized finance and proves once again: smart contracts require not only code, but also strategic security.

Other related articles
News
Read more
Data leak of over a million students due to cyberattack on the website of New York University:
A cyberattack on New York University (NYU) has exposed the personal data of more than a million students. This massive cyberattack resulted in a loss of privacy and confidentiality, including the names, addresses, phone numbers, and financial information of applicants and students. The incident highlights the importance of strengthening cybersecurity measures at educational institutions to avoid similar situations in the future.
119
News
Read more
Journalist accidentally learns about Yemen strike plans in Signal chat
A high-profile scandal in the US — a journalist became the owner of secret US military plans through a group chat in Signal, where the Trump administration planned strikes on Yemen. The information was leaked by mistake: the editor of *The Atlantic* was accidentally added to the chat. Among the participants were Vice President Vance, Pete Hegsetts, Stephen Miller and other high-ranking officials.
109
News
Read more
Sydney Tools data breach: Hackers could access over 34 million orders
Sydney Tools, one of Australia’s largest retailers, has suffered a massive data breach that exposed more than 34 million online orders and employee personal information, including salaries, addresses, email addresses, and phone numbers. The data breach occurred through an unsecured Clickhouse database and has not yet been patched.
128
Found an error?
If you find an error, take a screenshot and send it to the bot.