TLDR Abracadabra’s third exploit drains $1.7 million, exploiting smart contract flaws. Hackers laundered stolen funds via Tornado Cash after attacking Abracadabra. Abracadabra pauses contracts to limit further losses from the latest breach. Abracadabra’s prior hacks in 2024 and 2025 led to $19.5 million in losses. Abracadabra, a decentralized finance (DeFi) protocol, has fallen victim to [...] The post Abracadabra Faces Third DeFi Exploit as Hackers Drain $1.7 Million appeared first on CoinCentral.TLDR Abracadabra’s third exploit drains $1.7 million, exploiting smart contract flaws. Hackers laundered stolen funds via Tornado Cash after attacking Abracadabra. Abracadabra pauses contracts to limit further losses from the latest breach. Abracadabra’s prior hacks in 2024 and 2025 led to $19.5 million in losses. Abracadabra, a decentralized finance (DeFi) protocol, has fallen victim to [...] The post Abracadabra Faces Third DeFi Exploit as Hackers Drain $1.7 Million appeared first on CoinCentral.

Abracadabra Faces Third DeFi Exploit as Hackers Drain $1.7 Million

2025/10/06 01:51

TLDR

  • Abracadabra’s third exploit drains $1.7 million, exploiting smart contract flaws.
  • Hackers laundered stolen funds via Tornado Cash after attacking Abracadabra.
  • Abracadabra pauses contracts to limit further losses from the latest breach.
  • Abracadabra’s prior hacks in 2024 and 2025 led to $19.5 million in losses.

Abracadabra, a decentralized finance (DeFi) protocol, has fallen victim to its third major exploit. Hackers drained approximately $1.7 million from the platform, marking another setback for the project. The breach was first identified by blockchain security firm Go Security on October 4, 2025. This attack follows previous incidents in which the platform lost millions, raising concerns over its security measures.

How the Attack Unfolded

On October 4, Go Security reported the latest breach, revealing that hackers managed to exploit a vulnerability in Abracadabra’s smart contract. The attackers manipulated the platform’s contract variables, allowing them to bypass a solvency check. This exploitation let them borrow assets beyond the intended limit, resulting in a substantial loss for the protocol.

Weilin Li, a security researcher, confirmed the breach, explaining that the vulnerability occurred due to faulty logic in the smart contract. The attack took advantage of a sequence error within Abracadabra’s cook function, which is designed to execute multiple actions in a single transaction. According to Phalcon, another blockchain audit firm, the exploit occurred through two specific actions.

The first, called “action 5,” triggered a borrowing process intended to pass solvency checks. The second, labeled “action 0,” bypassed the validation step by overriding the check flag. The attackers repeated this process across six different addresses, stealing over 1.79 million MIM tokens in the process.

The Response from Abracadabra’s Team

Following the exploit, Abracadabra’s team quickly acted to prevent further damage. They paused all contracts on the platform to limit additional losses. At the time of reporting, the hacker’s wallet contained around 344 ETH, worth roughly $1.55 million, though the stolen funds had already been partially laundered through Tornado Cash.

Go Security noted that the Abracadabra team confirmed on Discord that it would use its DAO reserve funds to repurchase the affected MIM tokens. However, as of October 5, the official social media channels of Abracadabra, including its X account, remained silent on the incident. This lack of communication has raised concerns about the project’s ongoing transparency.

Previous Exploits Raise Concerns

This breach is not the first time Abracadabra has been targeted by attackers. In January 2024, the platform suffered a hack that resulted in a $6.49 million loss and briefly caused the MIM stablecoin to depeg from the US dollar. A second exploit in March 2025 drained an additional $13 million from Abracadabra’s cauldron contracts, leading the team to offer the hacker a 20% bounty in exchange for the stolen funds.

The recurrence of such breaches in a relatively short period has prompted ongoing questions about the security of the platform. Despite the team’s efforts to address vulnerabilities, these repeated attacks have damaged the project’s reputation and raised concerns about the sustainability of its cross-chain lending system.

The Future of Abracadabra’s Security

As the third exploit adds to the growing list of security issues, the DeFi space is left questioning how Abracadabra plans to strengthen its protocols moving forward. While the team’s response to the current exploit appears swift, it remains to be seen whether these actions will be enough to restore user trust and prevent further breaches.

The continued challenges faced by Abracadabra highlight the importance of robust security measures in the rapidly evolving DeFi sector. For now, the platform’s future security strategy will likely remain under scrutiny as both developers and users await clearer answers from the project’s team.

The post Abracadabra Faces Third DeFi Exploit as Hackers Drain $1.7 Million appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Share