{"investigation":{"slug":"credix","entity_name":"CrediX Finance","trust_score":4,"severity_base":null,"score_modifier":0,"confidence":0.87,"status":"published","content_type":"investigation","summary":"CrediX Finance was a DeFi lending protocol launched in July 2025 on the Sonic blockchain that suffered a $4.5 million exploit on August 4, 2025, less than one month after launch. The exploit involved a compromised or insider-controlled admin wallet that minted unbacked synthetic tokens to drain liquidity pools; the team subsequently vanished, deleted all official channels, and failed to honor public recovery promises, prompting widespread allegations of a premeditated exit scam. Note: CrediX Finance (Sonic, 2025) is a distinct entity from Credix Finance (Solana, founded 2021), which is a separate legitimate RWA protocol.","sections":[{"content":"CrediX Finance (stylized with capital X) was a DeFi lending and borrowing protocol deployed on the Sonic blockchain that went live in July 2025. It positioned itself as a real-world asset lending platform allowing borrowers to receive loans backed by off-chain income and collateral provided by DeFi liquidity providers. The protocol offered yield-bearing pools denominated in USDC and scUSD (Sonic's native stablecoin). CrediX Finance (Sonic, 2025) must be distinguished from Credix Finance (Solana, founded 2021), a separate, venture-backed private credit marketplace co-founded by Thomas Bohner (CEO), Maxim Piessen (CTO), and Chaim Feinberg (CBO), which raised $79.7 million from institutional investors including ParaFi Capital, Patria Investments, and Motive Partners. The two entities share a near-identical name but operate on different blockchains and are unrelated. All incidents described in this investigation concern CrediX Finance (Sonic).","heading":"Entity Overview and Name Disambiguation","sources":[{"url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2023/07/26/crypto-lender-credix-brings-opens-private-credit-pool-on-solana-with-11-yield","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 4, 2025 at approximately 09:10 UTC, CrediX Finance was drained of approximately $4.5 million in user funds. The attack exploited concentrated administrative privileges rather than a smart contract logic flaw. According to blockchain security firms SlowMist, CertiK, and QuillAudits, the exploit unfolded in two phases: six days prior to the attack, on or around July 29, 2025, a malicious account received sweeping administrative roles via the protocol's ACLManager contract from an admin externally-owned account (EOA) identified as 0x0dd010513F7abB8F9c628dC164a24D953BCA09Cf. The transaction granting these roles was recorded on-chain as 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae72e3b8e903334f35e. The attacker was granted five critical roles: POOL_ADMIN_ROLE (complete lending pool control), BRIDGE_ROLE (cross-chain minting capabilities), ASSET_LISTING_ADMIN_ROLE (authority to list new assets), EMERGENCY_ADMIN_ROLE (protocol shutdown powers), and RISK_ADMIN_ROLE (risk parameter authority). On August 4, the attacker used the BRIDGE_ROLE to mint approximately 2,500,000 unbacked acUSDC tokens and 3,250,000 unbacked acscUSD tokens without depositing any corresponding collateral. These artificially created tokens were then posted as collateral to borrow legitimate protocol assets. Stolen assets by category included: USDC ($2,036,501), wS tokens ($1,343,322), scUSD ($1,160,000), stS beets staked tokens ($55,578), and WETH ($45,558). Post-exploit, the stolen funds were converted to USDC and bridged from the Sonic network to Ethereum via deBridge, then distributed across three Ethereum wallets. According to CertiK, approximately half of the stolen funds — roughly 300 ETH — was subsequently laundered through Tornado Cash. Approximately 630 ETH (approximately $2.8 million at the time) remained in attacker-controlled wallets. The Halborn security firm classified the incident as insider-facilitated rather than a purely external attack, noting that the protocol's own multisig wallet directly assigned broad permissions to the attacker's account.","heading":"The $4.5 Million Exploit (August 4, 2025)","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/credix-finances-4-5m-exploit-96526a5119cc","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-credix-hack-august-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the August 4 exploit, the CrediX Finance team issued a public statement via X (Twitter) and Telegram claiming that all user funds would be recovered in full within 24 to 48 hours. The team alleged it had reached a negotiated agreement with the exploiter, under which the exploiter would return stolen funds in exchange for a payment from the CrediX treasury plus a token airdrop. No recovery occurred within the stated window. By approximately August 8, 2025, the team had gone completely silent: the protocol's official website was taken offline, the X account was deactivated, the Telegram channel was deleted, and the Discord server was shut down. The rapidity and completeness of the communication blackout — combined with the premeditated six-day staging period before the exploit — led multiple security researchers, publications, and affected protocols to allege that the incident was a coordinated exit scam rather than an external hack. The premeditated granting of admin roles six days before the exploit, the structured liquidation of assets, the use of Tornado Cash to launder proceeds, and the immediate disappearance after making false recovery promises are the primary bases for exit scam allegations. No member of the CrediX Finance team has been publicly identified by name as of the time of this investigation.","heading":"Alleged Exit Scam and Team Disappearance","sources":[{"url":"https://cointelegraph.com/news/credix-finance-team-disappears-after-4-5m-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/08/08/credix-team-suspectedly-pulls-off-exit-scam-after-4-5m-hack/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/exit-scam-credix-disappears-after-a-4-5m-hack/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://www.newsbtc.com/news/exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit/","name":"newsbtc.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Stability DAO, which had integrated CrediX Finance into its Metavaults product, emerged as the primary coordinating entity for recovery efforts following the exploit and team disappearance. The DAO announced it was filing a formal legal report with law enforcement cybercrime units and stated that its teams were 'collaborating to gather all evidence, trace the funds, and coordinate with relevant legal and cybercrime units.' Critically, Stability DAO confirmed it had obtained know-your-customer (KYC) documentation for two CrediX team members and indicated these identities would be included in the formal legal submission. The DAO published an advisory warning all users to avoid interacting with any CrediX smart contracts and announced plans for a compensation and recovery strategy for Metavault users. Additional affected protocols — including Sonic Labs, Euler Finance, Beets, and Trevee (Rines Protocol) — joined the coordinated response. Trevee reported reducing its direct CrediX exposure from $1.6 million to approximately $700,000 through preemptive liquidity management. As of the most recent reporting, no funds have been recovered and the legal proceedings remain ongoing.","heading":"Stability DAO Response and Legal Action","sources":[{"url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.cointribune.com/en/credix-finance-disappears-4-5m-hack/","name":"cointribune.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/credix-finance-team-disappears-after-4-5m-hack","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security auditors identified several structural vulnerabilities that either enabled or failed to prevent the attack. CertiK's post-incident analysis noted that one multisig signer held overlapping high-risk roles — specifically POOL_ADMIN and BRIDGE_CONTROLLER simultaneously — violating the principle of least privilege. The protocol had received a single formal audit, delivered January 22, 2022 (notably, this audit date predates the Sonic-based CrediX Finance's July 2025 launch and likely refers to the original Solana-based Credix Finance; it is unclear whether a separate audit was conducted for the Sonic deployment). The CertiK Skynet profile for the entity notes no active bug bounty program, no team KYC verification, and a low maturity rating. The protocol lacked timelocked governance for parameter changes or role assignments, meaning admin roles could be granted without any delay that would allow community oversight. The absence of real-time on-chain monitoring meant the staged privilege escalation six days before the exploit went undetected. Multiple post-mortems concluded that centralized admin key concentration represented the primary attack surface.","heading":"Security Architecture Failures and Red Flags","sources":[{"url":"https://skynet.certik.com/projects/credix","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-credix-hack-august-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://tokenvitals.com/blog/inside-credix-collapse-lessons-4-5m-defi-exit-scam","name":"tokenvitals.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit","name":"quillaudits.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain forensics conducted by CertiK and SlowMist traced the movement of stolen assets following the August 4, 2025 exploit. Stolen assets were first converted to USDC on the Sonic network, then bridged to Ethereum via the deBridge cross-chain protocol. Upon arrival on Ethereum, the funds were split across three separate externally-owned addresses. Approximately 300 ETH — representing roughly half of the total stolen value — was routed through Tornado Cash, the sanctioned Ethereum mixing service, to obscure the transaction trail. Approximately 630 ETH (approximately $2.8 million) remained in attacker-controlled wallets at the time of most recent reporting. The use of Tornado Cash to launder proceeds further complicated potential law enforcement recovery efforts and on-chain tracing by Stability DAO's forensic partners. The initial attack funding itself was also alleged to have originated through Tornado Cash, suggesting the attacker was experienced in obfuscation techniques.","heading":"Fund Movement and Laundering","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.thearizonatribune.com/credix-hack-funds-washed-tornado-cash/","name":"thearizonatribune.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/credix","name":"skynet.certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to AVOID.NET intake records, ZachXBT flagged CrediX as a high-risk entity. A specific public post from ZachXBT explicitly naming CrediX Finance (Sonic) could not be independently verified through open-source search at the time of this investigation. The circumstances of the exploit — including the six-day staged privilege escalation, insider-linked attack vector, and subsequent team disappearance — are consistent with the type of exit scam that ZachXBT routinely investigates and flags. The absence of a verifiable public post does not indicate the flag is inaccurate; ZachXBT conducts research across Telegram and private channels in addition to public X posts.","heading":"ZachXBT Flag","sources":[{"url":"https://www.coingabbar.com/en/crypto-currency-news/credix-finance-scam-or-defi-rug-pull-plot-millions-vanish","name":"coingabbar.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/credix-finance-team-suspected-exit-scam-4-5-million-hack-2508/","name":"ainvest.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-07","event":"CrediX Finance launches on the Sonic blockchain as a DeFi lending protocol, less than one month before the exploit.","source":"","date_original":"2025-07-01"},{"date":"2025-07-29","event":"Attacker granted POOL_ADMIN_ROLE, BRIDGE_ROLE, ASSET_LISTING_ADMIN_ROLE, EMERGENCY_ADMIN_ROLE, and RISK_ADMIN_ROLE via the ACLManager contract by a CrediX admin EOA (0x0dd010513F7abB8F9c628dC164a24D953BCA09Cf). Transaction hash: 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae72e3b8e903334f35e.","source":""},{"date":"2025-08-04","event":"Exploit executed at approximately 09:10 UTC. Attacker mints 2,500,000 unbacked acUSDC and 3,250,000 unbacked acscUSD, uses them as collateral to drain $4.5M in user funds. Protocol taken offline. Stolen assets bridged from Sonic to Ethereum via deBridge.","source":""},{"date":"2025-08-04","event":"CrediX Finance posts statement on X claiming 'All users funds will be recovered in full within 24-48 hours' and alleges a negotiated return deal with the exploiter.","source":""},{"date":"2025-08-05","event":"CertiK confirms stolen assets distributed across three Ethereum wallets. Approximately half (300 ETH) subsequently routed through Tornado Cash.","source":""},{"date":"2025-08-08","event":"CrediX Finance team goes completely dark. Website remains offline, X account deactivated, Telegram channel deleted, Discord shut down. No fund recovery occurs. CertiK publicly reports the disappearance.","source":""},{"date":"2025-08-08","event":"Stability DAO announces it is filing a formal legal report with cybercrime authorities, confirms KYC data for two CrediX team members has been obtained and will be submitted to law enforcement.","source":""},{"date":"2025-08-09","event":"Multiple affected protocols — Sonic Labs, Euler, Beets, Trevee — join Stability DAO's coordinated legal and recovery effort. Trevee reduces its CrediX exposure from $1.6M to approximately $700K.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915164959/https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit","credibility":3,"archive_timestamp":"2026-09-15T16:49:59+00:00"},{"url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260518092755/https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report","credibility":3,"archive_timestamp":"2026-05-18T09:27:55+00:00"},{"url":"https://www.coindesk.com/markets/2023/07/26/crypto-lender-credix-brings-opens-private-credit-pool-on-solana-with-11-yield","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251129203524/https://www.coindesk.com/markets/2023/07/26/crypto-lender-credix-brings-opens-private-credit-pool-on-solana-with-11-yield","credibility":3,"archive_timestamp":"2025-11-29T20:35:24+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260626173340/https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit","credibility":3,"archive_timestamp":"2026-06-26T17:33:40+00:00"},{"url":"https://quillaudits.medium.com/credix-finances-4-5m-exploit-96526a5119cc","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017172938/https://quillaudits.medium.com/credix-finances-4-5m-exploit-96526a5119cc","credibility":3,"archive_timestamp":"2025-10-17T17:29:38+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-credix-hack-august-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260513002634/https://www.halborn.com/blog/post/explained-the-credix-hack-august-2025","credibility":3,"archive_timestamp":"2026-05-13T00:26:34+00:00"},{"url":"https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260420091033/https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit","credibility":3,"archive_timestamp":"2026-04-20T09:10:33+00:00"},{"url":"https://cointelegraph.com/news/credix-finance-team-disappears-after-4-5m-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260315110415/https://cointelegraph.com/news/credix-finance-team-disappears-after-4-5m-hack","credibility":3,"archive_timestamp":"2026-03-15T11:04:15+00:00"},{"url":"https://www.cryptotimes.io/2025/08/08/credix-team-suspectedly-pulls-off-exit-scam-after-4-5m-hack/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260801032020/https://www.cryptotimes.io/2025/08/08/credix-team-suspectedly-pulls-off-exit-scam-after-4-5m-hack/","credibility":3,"archive_timestamp":"2026-08-01T03:20:20+00:00"},{"url":"https://www.cryptopolitan.com/exit-scam-credix-disappears-after-a-4-5m-hack/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20251014110745/https://www.cryptopolitan.com/exit-scam-credix-disappears-after-a-4-5m-hack/","credibility":3,"archive_timestamp":"2025-10-14T11:07:45+00:00"},{"url":"https://www.newsbtc.com/news/exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit/","name":"newsbtc.com","type":"other","archive_url":"http://web.archive.org/web/20260216225951/https://www.newsbtc.com/news/exit-scam-defi-protocol-credixs-team-vanishes-following-4-5-million-exploit/","credibility":3,"archive_timestamp":"2026-02-16T22:59:51+00:00"},{"url":"https://www.cointribune.com/en/credix-finance-disappears-4-5m-hack/","name":"cointribune.com","type":"other","archive_url":"http://web.archive.org/web/20250916172057/https://www.cointribune.com/en/credix-finance-disappears-4-5m-hack/","credibility":3,"archive_timestamp":"2025-09-16T17:20:57+00:00"},{"url":"https://skynet.certik.com/projects/credix","name":"skynet.certik.com","type":"other","archive_url":"http://web.archive.org/web/20260801001541/https://skynet.certik.com/projects/credix","credibility":3,"archive_timestamp":"2026-08-01T00:15:41+00:00"},{"url":"https://tokenvitals.com/blog/inside-credix-collapse-lessons-4-5m-defi-exit-scam","name":"tokenvitals.com","type":"other","archive_url":"https://web.archive.org/web/20260829082606/https://tokenvitals.com/blog/inside-credix-collapse-lessons-4-5m-defi-exit-scam","credibility":3,"archive_timestamp":"2026-08-29T08:26:06+00:00"},{"url":"https://www.thearizonatribune.com/credix-hack-funds-washed-tornado-cash/","name":"thearizonatribune.com","type":"other","archive_url":"http://web.archive.org/web/20260309084528/https://www.thearizonatribune.com/credix-hack-funds-washed-tornado-cash/","credibility":3,"archive_timestamp":"2026-03-09T08:45:28+00:00"},{"url":"https://www.coingabbar.com/en/crypto-currency-news/credix-finance-scam-or-defi-rug-pull-plot-millions-vanish","name":"coingabbar.com","type":"other","archive_url":"https://web.archive.org/web/20260829045324/https://www.coingabbar.com/en/crypto-currency-news/credix-finance-scam-or-defi-rug-pull-plot-millions-vanish","credibility":3,"archive_timestamp":"2026-08-29T04:53:24+00:00"},{"url":"https://www.ainvest.com/news/credix-finance-team-suspected-exit-scam-4-5-million-hack-2508/","name":"ainvest.com","type":"other","archive_url":"http://web.archive.org/web/20260801001914/https://www.ainvest.com/news/credix-finance-team-suspected-exit-scam-4-5-million-hack-2508/","credibility":3,"archive_timestamp":"2026-08-01T00:19:14+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:19.643481+00:00","updated_at":"2026-09-15T17:10:50.151966+00:00"}}