{"investigation":{"slug":"unibtc","entity_name":"uniBTC","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"uniBTC is a synthetic Bitcoin liquid restaking token issued by Bedrock protocol, enabling wBTC holders to earn BTC-native yield via the Babylon staking protocol while retaining liquidity. In September 2024, a critical minting vulnerability in multiple uniBTC vault smart contracts across eight blockchains was exploited for approximately $2 million after a third-party security firm disclosed the flaw hours before the attack. Post-incident forensics by Fuzzland, disclosed in June 2025, attributed the exploit to an insider threat — a former employee who embedded malware into Fuzzland's internal codebase and used privileged access to execute the attack; Bedrock has since integrated Chainlink Proof of Reserve and expanded to multiple new chains.","sections":[{"content":"uniBTC is an ERC-20 liquid restaking token created by Bedrock, a multi-asset liquid restaking protocol. When users deposit wrapped Bitcoin (wBTC) into Bedrock vaults, they receive uniBTC at a 1:1 ratio, with staking rewards accruing in the token's value. The protocol partnered with Babylon Chain, a Bitcoin proof-of-stake protocol, to generate BTC-native yields. At its peak, Bedrock reported approximately $700 million in total value locked across more than 15 supported chains including Ethereum, Binance Smart Chain, Arbitrum, Optimism, Mantle, Mode, BOB, ZetaChain, Berachain, and Aptos. uniBTC can be used as collateral, in liquidity provision, and in yield farming on supported DeFi protocols, and trades on Uniswap V3, PancakeSwap, Velodrome, and other decentralized exchanges.","heading":"Protocol Overview","sources":[{"url":"https://docs.bedrock.technology/multi-asset-liquid-staking/unibtc/introduction","name":"docs.bedrock.technology","type":"other","credibility":3},{"url":"https://defillama.com/protocol/bedrock-unibtc","name":"defillama.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x004e9c3ef86bc1ca1f0bb5c7662861ee93350568","name":"etherscan.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 26, 2024, Web3 security firm Dedaub discovered a critical vulnerability in multiple uniBTC vault smart contracts deployed across at least eight blockchains. The root cause was a mismatched exchange rate calculation in the minting logic: the function `_mint(msg.sender, msg.value)` scaled only for decimal differences between ETH (18 decimals) and uniBTC (8 decimals), but failed to account for the substantial price differential between ETH and BTC. This allowed any user depositing ETH to mint uniBTC in equal nominal quantities, enabling instant arbitrage profit. At approximately 16:00 UTC on September 26, Dedaub confirmed the vulnerability; at 16:27 UTC it was reported to Bedrock via Twitter; at 16:41 UTC a war room was created on the SEAL 911 platform. Despite disclosure, most of the Bedrock team was unavailable due to time-zone differences. At 18:28 UTC — roughly two hours after discovery — the first exploit transaction executed on Ethereum. The attacker minted approximately 30.8 uniBTC without proper value input, swapped them for 27.8 WBTC via Uniswap, and converted those to approximately 680.4 WETH, repaying a flash loan of 30.8 WETH and netting roughly 649.6 WETH (approximately $1.7 million). Total losses including secondary DEX liquidity pools were estimated at approximately $2 million. Stolen funds were subsequently routed through Tornado Cash. Attacker wallet addresses identified by on-chain analysis include 0x2bFB373017349820dda2Da8230E6b66739BE9F96, 0xEE800b1b63893Ca1E1b0FA8fEfDc10fAc9B980f7, and attacker-created contract 0x0C8da4f8B823bEe4D5dAb73367D45B5135B50faB. Dedaub coordinated with Pendle Finance to disable uniBTC on their platform, protecting over $30 million in liquidity, and the vulnerable vaults were ultimately paused — limiting potential total losses which could have reached $75 million.","heading":"Smart Contract Exploit — September 2024","sources":[{"url":"https://dedaub.com/blog/bedrock-vulnerability-disclosure-and-actions/","name":"dedaub.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/liquid-restaking-protocol-bedrock-suffers-2-million-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/hacks/bedrock-vulnerability-allows-hacker-to-drain-usd2m-from-unibtc-liquidity-pools","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/bedrock-2million-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://blockapex.io/unibtc-hack-analysis/","name":"blockapex.io","type":"other","credibility":3},{"url":"https://lunaray.medium.com/bedrock-unibtc-hack-analysis-7808902e5a7c","name":"lunaray.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In June 2025, smart contract security firm Fuzzland published a transparency report disclosing that a former employee was responsible for the September 2024 Bedrock uniBTC exploit. According to Fuzzland, the individual was hired under the guise of a skilled MEV (maximal extractable value) developer. On or around September 4, 2024, the attacker modified Fuzzland's project `Cargo.toml` file to include a malicious Rust crate named `rands`, effectively embedding a trojan that auto-executed in commonly used developer IDEs such as VSCode and JetBrains. This malware granted persistent, undetected access to engineering workstations for over three weeks. On September 26, 2024, Fuzzland held an emergency call to discuss the vulnerability identified in the Dedaub report; the insider, having access to this session and the sensitive technical details it contained, appears to have triggered or facilitated the exploit approximately one hour after that call concluded. Fuzzland's report states that no client or customer data beyond the exploit itself was affected, and that Fuzzland accepted full responsibility and reimbursed all affected parties. The identity of the former employee has not been publicly confirmed in available sources, and no law enforcement charges have been publicly reported as of May 2026.","heading":"Insider Threat — Fuzzland Disclosure (June 2025)","sources":[{"url":"https://cointelegraph.com/news/fuzzland-ex-employee-bedrock-unibtc-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/ex-employee-hacks-bedrock-unibtc-for-2m-fuzzland-uncovers-insider-exploit/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://www.bitdegree.org/crypto/news/fuzzland-breach-tied-to-ex-employee-in-2-million-unibtc-exploit","name":"bitdegree.org","type":"other","credibility":3},{"url":"https://news.shib.io/2025/06/26/fuzzland-reveals-insider-behind-2m-unibtc-hack-at-bedrock/","name":"news.shib.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the September 2024 exploit, the uniBTC contracts had received audits from multiple firms. Blocksec audited the protocol on June 12, 2024 and again on October 30, 2024 (post-incident). PeckShield conducted an audit on October 1, 2024. Despite these audits, the vulnerable vault contract that was exploited was deployed only approximately 36 hours before the attack, and the minting flaw went undetected. The Dedaub team identified the critical issue externally. A key failure was the inability of the Bedrock team to respond within the approximate two-hour window between vulnerability disclosure and exploitation, attributed to team members being asleep across different time zones. The existence of an emergency response channel (SEAL 911) was appropriate, but the lack of around-the-clock monitoring of newly deployed contracts represented an operational security gap.","heading":"Security Audit History and Pre-Exploit Failures","sources":[{"url":"https://docs.bedrock.technology/security/audit-reports","name":"docs.bedrock.technology","type":"other","credibility":3},{"url":"https://dedaub.com/blog/bedrock-vulnerability-disclosure-and-actions/","name":"dedaub.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/bedrock-2million-exploit","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.fxleaders.com/news/2024/09/29/bedrock-boosts-security-after-2m-exploit-with-chainlink-integration-and-audits/","name":"fxleaders.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Bedrock issued a public statement acknowledging approximately $2 million in losses, concentrated in DEX liquidity pools rather than core protocol collateral, and stated that all uniBTC collateral backing remained intact. Bedrock published a post-mortem report on September 28, 2024 (via its X account at @Bedrock_DeFi) and committed to a comprehensive reimbursement plan for affected users. The protocol also extended a job offer to the attacker — a common whitehacking tactic — though no response was publicly reported. As a security remediation measure, Bedrock integrated Chainlink Proof of Reserve (PoR) Secure Mint, which programmatically verifies sufficient on-chain collateral before any token issuance, reverting transactions automatically if reserves are insufficient. The protocol subsequently expanded its footprint: contributing approximately 1,000 uniBTC to Berachain's Boyco campaign in early 2025 and launching on Aptos in September 2025. As of mid-2025, Bedrock reported TVL exceeding $530 million.","heading":"Post-Exploit Response and Remediation","sources":[{"url":"https://x.com/Bedrock_DeFi/status/1839712719630676051","name":"x.com","type":"other","credibility":3},{"url":"https://blockonomi.com/bedrock-protocol-reports-2m-exploit-reimbursement-plan-in-progress/","name":"blockonomi.com","type":"other","credibility":3},{"url":"https://chainlinktoday.com/after-2-million-exploit-bedrock-turns-to-chainlink-proof-of-reserve-for-secure-minting/","name":"chainlinktoday.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/bedrock-chainlink-integration-security/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://beincrypto.com/bedrock-integrates-chainlink-2-million-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.prnewswire.com/news-releases/bedrock-launches-unibtc-and-brbtc-on-aptos-expanding-the-frontiers-of-btcfi-302546744.html","name":"prnewswire.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT flagged uniBTC and the Bedrock exploit in connection with his broader analysis of the September 2024 incident. According to reporting based on ZachXBT's Investigations Telegram channel, he traced losses and identified addresses linked to the protocol's treasury multisig and personal wallets. The specific nature and scope of ZachXBT's independent findings versus those of Dedaub and Fuzzland have not been fully reconciled in available public sources. No regulatory filings or law enforcement actions related to uniBTC, Bedrock, or the identified attacker wallets have been publicly confirmed as of May 2026.","heading":"ZachXBT Flagging","sources":[{"url":"https://cryptonews.net/news/security/29852647/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/09/27/bedrock-faces-2-million-loss-in-unibtc-security-breach/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"No regulatory actions by the SEC, CFTC, DOJ, or equivalent international bodies against Bedrock or uniBTC have been identified in available public records as of May 2026. The attacker's use of Tornado Cash for fund obfuscation is consistent with patterns flagged in prior OFAC-sanctioned mixing service enforcement, but no specific enforcement action related to this exploit has been publicly filed. The insider threat vector — a malicious employee embedding malware in a security firm's codebase — may have civil law implications for Fuzzland, though no lawsuits have been publicly identified. Fuzzland voluntarily accepted responsibility and reimbursed affected parties.","heading":"Regulatory and Legal Status","sources":[{"url":"https://cointelegraph.com/news/fuzzland-ex-employee-bedrock-unibtc-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/ex-employee-hacks-bedrock-unibtc-for-2m-fuzzland-uncovers-insider-exploit/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-06-12","event":"Blocksec conducts initial audit of uniBTC contracts.","source":""},{"date":"2024-09-04","event":"Alleged insider (later identified as a former Fuzzland employee) modifies Cargo.toml to include malicious Rust crate 'rands', embedding malware in Fuzzland workstations.","source":""},{"date":"2024-09-25","event":"Vulnerable uniBTC vault contract deployed approximately 36 hours before the exploit.","source":""},{"date":"2024-09-26","event":"16:00 UTC — Dedaub discovers and confirms the critical infinite-mint vulnerability in uniBTC vault contracts across 8 chains.","source":""},{"date":"2024-09-26","event":"16:27 UTC — Dedaub reports vulnerability to Bedrock via Twitter. 16:41 UTC — SEAL 911 war room created.","source":""},{"date":"2024-09-26","event":"Emergency call held between Fuzzland and relevant parties to discuss the Dedaub-identified vulnerability. Insider with privileged access participates.","source":""},{"date":"2024-09-26","event":"18:28 UTC — First exploit transaction executes on Ethereum. Attacker mints ~30.8 uniBTC, swaps to WBTC via Uniswap, converts to ~680 WETH, nets ~649.6 WETH (~$1.7M) after repaying flash loan.","source":""},{"date":"2024-09-26","event":"Bedrock coordinates with Pendle Finance to disable uniBTC exposure, protecting over $30M in liquidity. Vulnerable vaults paused across 8 chains.","source":""},{"date":"2024-09-27","event":"Bedrock publicly acknowledges exploit. Estimates total losses at approximately $2 million, primarily in DEX liquidity pools. Announces reimbursement plan.","source":""},{"date":"2024-09-27","event":"Stolen funds routed through Tornado Cash mixing service.","source":""},{"date":"2024-09-28","event":"Bedrock publishes post-mortem report via X (@Bedrock_DeFi). Extends job offer to attacker; no response publicly reported.","source":""},{"date":"2024-09-29","event":"Bedrock announces Chainlink Proof of Reserve Secure Mint integration as primary security remediation. PeckShield conducts post-incident audit (completed October 1, 2024). Blocksec conducts second audit (completed October 30, 2024).","source":""},{"date":"2025-02-05","event":"Bedrock contributes approximately 1,000 uniBTC to Berachain's Boyco campaign; Boyco TVL reaches $3 billion.","source":""},{"date":"2025-06-26","event":"Fuzzland publishes transparency report disclosing that a former employee was behind the September 2024 exploit using supply chain malware, social engineering, and privileged access. Fuzzland accepts full responsibility and states all affected parties were reimbursed.","source":""},{"date":"2025-09-04","event":"Bedrock launches uniBTC and brBTC on the Aptos blockchain, reporting nearly $700M in TVL and over 5,000 BTC staked across 15+ chains.","source":""}],"sources_used":[{"url":"https://docs.bedrock.technology/multi-asset-liquid-staking/unibtc/introduction","name":"docs.bedrock.technology","type":"other","archive_url":"http://web.archive.org/web/20260608073007/https://docs.bedrock.technology/multi-asset-liquid-staking/unibtc/introduction","credibility":3,"archive_timestamp":"2026-06-08T07:30:07+00:00"},{"url":"https://defillama.com/protocol/bedrock-unibtc","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250909133232/https://defillama.com/protocol/bedrock-unibtc","credibility":3,"archive_timestamp":"2025-09-09T13:32:32+00:00"},{"url":"https://etherscan.io/token/0x004e9c3ef86bc1ca1f0bb5c7662861ee93350568","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260703214156/https://etherscan.io/token/0x004E9C3EF86bc1ca1f0bB5C7662861Ee93350568","credibility":3,"archive_timestamp":"2026-07-03T21:41:56+00:00"},{"url":"https://dedaub.com/blog/bedrock-vulnerability-disclosure-and-actions/","name":"dedaub.com","type":"other","archive_url":"http://web.archive.org/web/20260219103007/https://dedaub.com/blog/bedrock-vulnerability-disclosure-and-actions/","credibility":3,"archive_timestamp":"2026-02-19T10:30:07+00:00"},{"url":"https://cointelegraph.com/news/liquid-restaking-protocol-bedrock-suffers-2-million-exploit","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260725201434/https://cointelegraph.com/news/liquid-restaking-protocol-bedrock-suffers-2-million-exploit","credibility":3,"archive_timestamp":"2026-07-25T20:14:34+00:00"},{"url":"https://thedefiant.io/news/hacks/bedrock-vulnerability-allows-hacker-to-drain-usd2m-from-unibtc-liquidity-pools","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.quillaudits.com/blog/hack-analysis/bedrock-2million-exploit","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260421014515/https://www.quillaudits.com/blog/hack-analysis/bedrock-2million-exploit","credibility":3,"archive_timestamp":"2026-04-21T01:45:15+00:00"},{"url":"https://blockapex.io/unibtc-hack-analysis/","name":"blockapex.io","type":"other","archive_url":"http://web.archive.org/web/20260308141308/https://blockapex.io/unibtc-hack-analysis/","credibility":3,"archive_timestamp":"2026-03-08T14:13:08+00:00"},{"url":"https://lunaray.medium.com/bedrock-unibtc-hack-analysis-7808902e5a7c","name":"lunaray.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/fuzzland-ex-employee-bedrock-unibtc-exploit","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260725201421/https://cointelegraph.com/news/fuzzland-ex-employee-bedrock-unibtc-exploit","credibility":3,"archive_timestamp":"2026-07-25T20:14:21+00:00"},{"url":"https://cryptonews.com/news/ex-employee-hacks-bedrock-unibtc-for-2m-fuzzland-uncovers-insider-exploit/","name":"cryptonews.com","type":"other","archive_url":"http://web.archive.org/web/20251220105632/https://cryptonews.com/news/ex-employee-hacks-bedrock-unibtc-for-2m-fuzzland-uncovers-insider-exploit/","credibility":3,"archive_timestamp":"2025-12-20T10:56:32+00:00"},{"url":"https://www.bitdegree.org/crypto/news/fuzzland-breach-tied-to-ex-employee-in-2-million-unibtc-exploit","name":"bitdegree.org","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://news.shib.io/2025/06/26/fuzzland-reveals-insider-behind-2m-unibtc-hack-at-bedrock/","name":"news.shib.io","type":"other","archive_url":"http://web.archive.org/web/20260213110836/https://news.shib.io/2025/06/26/fuzzland-reveals-insider-behind-2m-unibtc-hack-at-bedrock/","credibility":3,"archive_timestamp":"2026-02-13T11:08:36+00:00"},{"url":"https://docs.bedrock.technology/security/audit-reports","name":"docs.bedrock.technology","type":"other","archive_url":"http://web.archive.org/web/20260608090336/https://docs.bedrock.technology/security/audit-reports","credibility":3,"archive_timestamp":"2026-06-08T09:03:36+00:00"},{"url":"https://www.fxleaders.com/news/2024/09/29/bedrock-boosts-security-after-2m-exploit-with-chainlink-integration-and-audits/","name":"fxleaders.com","type":"other","archive_url":"http://web.archive.org/web/20260306024250/https://www.fxleaders.com/news/2024/09/29/bedrock-boosts-security-after-2m-exploit-with-chainlink-integration-and-audits/","credibility":3,"archive_timestamp":"2026-03-06T02:42:50+00:00"},{"url":"https://x.com/Bedrock_DeFi/status/1839712719630676051","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://blockonomi.com/bedrock-protocol-reports-2m-exploit-reimbursement-plan-in-progress/","name":"blockonomi.com","type":"other","archive_url":"https://web.archive.org/web/20260829124418/https://blockonomi.com/solana-targets-a-new-all-time-high-but-smart-investors-are-betting-on-a-2000-surge-from-this-sol-rival/","credibility":3,"archive_timestamp":"2026-08-29T12:44:18+00:00"},{"url":"https://chainlinktoday.com/after-2-million-exploit-bedrock-turns-to-chainlink-proof-of-reserve-for-secure-minting/","name":"chainlinktoday.com","type":"other","archive_url":"http://web.archive.org/web/20260725200753/https://chainlinktoday.com/after-2-million-exploit-bedrock-turns-to-chainlink-proof-of-reserve-for-secure-minting/","credibility":3,"archive_timestamp":"2026-07-25T20:07:53+00:00"},{"url":"https://cryptobriefing.com/bedrock-chainlink-integration-security/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260124172659/https://cryptobriefing.com/bedrock-chainlink-integration-security/","credibility":3,"archive_timestamp":"2026-01-24T17:26:59+00:00"},{"url":"https://beincrypto.com/bedrock-integrates-chainlink-2-million-exploit/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260213031651/https://beincrypto.com/bedrock-integrates-chainlink-2-million-exploit/","credibility":3,"archive_timestamp":"2026-02-13T03:16:51+00:00"},{"url":"https://www.prnewswire.com/news-releases/bedrock-launches-unibtc-and-brbtc-on-aptos-expanding-the-frontiers-of-btcfi-302546744.html","name":"prnewswire.com","type":"other","archive_url":"http://web.archive.org/web/20260515230721/https://www.prnewswire.com/news-releases/bedrock-launches-unibtc-and-brbtc-on-aptos-expanding-the-frontiers-of-btcfi-302546744.html","credibility":3,"archive_timestamp":"2026-05-15T23:07:21+00:00"},{"url":"https://cryptonews.net/news/security/29852647/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829131746/https://cryptonews.net/news/security/29852647/","credibility":3,"archive_timestamp":"2026-08-29T13:17:46+00:00"},{"url":"https://www.cryptotimes.io/2024/09/27/bedrock-faces-2-million-loss-in-unibtc-security-breach/","name":"cryptotimes.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:28.669512+00:00","updated_at":"2026-08-30T05:14:05.778017+00:00"}}