{"investigation":{"slug":"unleash-protocol","entity_name":"Unleash Protocol","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Unleash Protocol is a decentralized intellectual property finance (IPFi) platform built on the Story Protocol blockchain, launched in early 2024. On December 30, 2025, the protocol suffered a confirmed $3.9 million exploit in which an attacker gained unauthorized administrative control through its multisignature governance system, executed an unauthorized smart contract upgrade, and laundered 1,337 ETH through Tornado Cash. The protocol subsequently paused all operations; as of early 2026 no recovery or user compensation plan has been publicly confirmed.","sections":[{"content":"On December 30, 2025, Unleash Protocol announced it had suffered a critical security incident resulting in the loss of approximately $3.9 million in user funds. Blockchain security firm PeckShield first flagged the incident, which was corroborated by on-chain analytics firm LookonChain and separately reported by CoinDesk, BleepingComputer, and other outlets.\n\nAn externally owned address obtained administrative signing authority within Unleash Protocol's multisignature governance framework. With that elevated access, the attacker executed an unauthorized smart contract upgrade that bypassed normal governance approval procedures and enabled direct asset withdrawals. The breach affected five asset classes held within platform contracts: WIP (Wrapped IP), USDC, WETH (Wrapped Ether), stIP (Staked IP), and vIP (Vote-escrowed IP).\n\nOn-chain analysis by PeckShield and CertiK traced the movement of stolen assets. The attacker bridged funds from the Story chain to Ethereum mainnet and subsequently deposited 1,337.1 ETH into Tornado Cash — a privacy mixer that was sanctioned by the U.S. Treasury in 2022 and later delisted in 2025 — in a series of structured transactions spanning 11 to 12 hours. The structured batching (multiple 1 ETH, 10 ETH, and 100 ETH tranches from a single compromised wallet with consistent network fees of 0.0028–0.0030 ETH per transaction) indicates deliberate planning consistent with money laundering tradecraft.\n\nCompliance analytics firm Scorechain noted that the attack executed as technically valid, on-chain authorized activity, evading conventional transaction-monitoring systems because governance-layer abuse is indistinguishable from legitimate administrative operations at the contract level.","heading":"Security Exploit — $3.9M Governance Breach (December 2025)","sources":[{"url":"https://www.coindesk.com/business/2025/12/30/unleash-protocol-hit-by-usd3-9-million-exploit-with-funds-routed-through-tornado-cash","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/unleash-protocol-hack-drains-3-9m-after-multisig-exploit-peckshield-reveals/","name":"coinpedia.org","type":"other","credibility":3},{"url":"https://coinmarketcap.com/academy/article/unleash-protocol-loses-dollar39m-in-governance-exploit","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.scorechain.com/blog/unleash-protocol-incident-shows-how-governance-failures-escalate-risk","name":"scorechain.com","type":"other","credibility":3},{"url":"https://coinjournal.net/news/how-a-governance-failure-led-to-the-unleash-protocol-hack/","name":"coinjournal.net","type":"other","credibility":3}],"severity":"medium"},{"content":"Security analysts and post-mortem coverage identified the root cause of the exploit as systemic governance design weaknesses rather than a flaw in Story Protocol's underlying infrastructure. Unleash Protocol itself confirmed in its post-incident statement that 'there is no evidence of compromise to Story Protocol contracts, validators, or underlying infrastructure,' isolating the failure to Unleash's own permission framework.\n\nThe specific failure mode involved insufficient enforcement of admin permission gating within the multisig system. An external actor obtained enough signing authority to act as a protocol administrator — either through key compromise, social engineering, or an undisclosed insider vector — and the governance system did not prevent execution of an unapproved contract upgrade. The use of SafeProxyFactory to establish the externally owned account was flagged by CertiK as part of the attack setup.\n\nCoinJournal and Scorechain observed that the attack's structured, deliberate execution pattern — with 24 outgoing transactions from the compromised multisig routed to a single destination cluster in a narrow time window — suggests the attacker had foreknowledge of system mechanics. The root cause investigation was ongoing as of available reporting, and Unleash did not publicly confirm whether the signing keys were externally compromised or whether an insider was involved.","heading":"Governance Design Failures","sources":[{"url":"https://coinjournal.net/news/how-a-governance-failure-led-to-the-unleash-protocol-hack/","name":"coinjournal.net","type":"other","credibility":3},{"url":"https://www.scorechain.com/blog/unleash-protocol-incident-shows-how-governance-failures-escalate-risk","name":"scorechain.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/unleash-protocol-hack-drains-3-9m-after-multisig-exploit-peckshield-reveals/","name":"coinpedia.org","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","name":"bleepingcomputer.com","type":"other","credibility":3}],"severity":"medium"},{"content":"After draining WIP, USDC, WETH, stIP, and vIP tokens from Unleash Protocol's contracts on the Story chain, the attacker bridged the proceeds to Ethereum mainnet using third-party bridge infrastructure. The total ETH-equivalent proceeds of approximately 1,337.1 ETH were then deposited into Tornado Cash, a transaction privacy protocol previously sanctioned by the U.S. Office of Foreign Assets Control (OFAC) in August 2022 for allegedly laundering over $7 billion for criminal actors including the Lazarus Group, a North Korean state-sponsored hacking unit.\n\nDeposits into Tornado Cash were executed across 34 transactions in 11–12 hours in a structured pattern of multiple 1 ETH, 10 ETH, and 100 ETH denomination batches, all originating from the same compromised wallet. This transaction structuring pattern is associated with deliberate anti-forensic behavior intended to frustrate blockchain analytics.\n\nThe use of Tornado Cash severely reduces the prospect of on-chain fund recovery. BleepingComputer noted that once funds enter a mixer of this type, direct recovery is highly unlikely absent law enforcement seizure or attacker cooperation.","heading":"Fund Flow and Tornado Cash Usage","sources":[{"url":"https://www.coindesk.com/business/2025/12/30/unleash-protocol-hit-by-usd3-9-million-exploit-with-funds-routed-through-tornado-cash","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/31/unleash-protocol-exploit-3-9m-stolen-via-multisig-governance-breach/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.scorechain.com/blog/unleash-protocol-incident-shows-how-governance-failures-escalate-risk","name":"scorechain.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following detection of the exploit on December 30, 2025, Unleash Protocol paused all platform operations and issued a public advisory urging users to avoid interacting with any Unleash Protocol smart contracts until official safety clearance was announced. The protocol engaged independent security experts and forensic investigators to determine the root cause of the governance breach.\n\nUnleash Protocol stated in its public communications that the incident occurred 'outside our intended governance and operational procedures.' The team emphasized that Story Protocol's core infrastructure was not affected.\n\nAs of available reporting through early 2026, no public announcement of a recovery plan, user compensation mechanism, or restart timeline had been issued. DefiLlama data showed Unleash Protocol's total value locked (TVL) at $0 following the incident, with no fees, revenue, or active loan metrics. The protocol's operational status remains paused.","heading":"Protocol Response and Operational Status","sources":[{"url":"https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/unleash-protocol-unauthorized-withdrawals/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/unleash-protocol","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/unleash-protocol-hack-drains-3-9m-after-multisig-exploit-peckshield-reveals/","name":"coinpedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Unleash Protocol's official documentation describes a team of 11 core members founded in early 2024, with backgrounds said to include major mainnet foundations, a top consulting firm, and a large broadcast organization. The documentation references experience in IP, web application security, development, and cryptocurrency. However, no individual team member names, LinkedIn profiles, or verifiable identities are disclosed in the publicly available documentation.\n\nThe absence of named, verifiable leadership is a recognized risk factor in DeFi projects, as it limits accountability in the event of an exploit or governance failure. The team's anonymity was not independently flagged as a concern prior to the December 2025 incident, but the subsequent governance breach — combined with the lack of public identity — complicates efforts to assess whether the incident was the result of external attack or internal misconduct.","heading":"Team Transparency and Identity","sources":[{"url":"https://docs.unleashprotocol.xyz/others/team","name":"docs.unleashprotocol.xyz","type":"other","credibility":3},{"url":"https://coinjournal.net/news/how-a-governance-failure-led-to-the-unleash-protocol-hack/","name":"coinjournal.net","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit triggered concern across the Story Protocol ecosystem. Reports indicated that the IP token (Story Protocol's native asset) experienced a price dip following the incident, as market participants feared contagion or reputational damage to the Story ecosystem despite Unleash's confirmation that the underlying Story Protocol was not compromised.\n\nPre-exploit, Unleash Protocol held approximately $4.4 million in TVL, positioning it as a modest but notable participant in the Story-based IPFi (Intellectual Property Finance) ecosystem alongside projects such as Verio and Color. The loss of $3.9 million — representing roughly 89% of the protocol's TVL — effectively rendered the protocol insolvent to its depositors.\n\nThe incident was cited in broader 2025 DeFi security reporting, with one source noting that 200 DeFi hacks occurred in 2025 with $2.9 billion stolen across the year, up from $2 billion in 2024.","heading":"Market and Ecosystem Impact","sources":[{"url":"https://bitcoinethereumnews.com/tech/unleash-protocol-exploit-causes-3-9m-loss-ip-token-dips-on-story-concerns/","name":"bitcoinethereumnews.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/unleash-protocol","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.scworld.com/brief/crypto-heist-pilfers-about-3-9m-from-unleash-protocol","name":"scworld.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/12/31/unleash-protocol-exploit-3-9m-stolen-via-multisig-governance-breach/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024","event":"Unleash Protocol founded by 11-member team, positioning as an IPFi (Intellectual Property Finance) platform on Story Protocol.","source":"","date_original":"2024-01-01"},{"date":"2025-12-30","event":"Attacker gains unauthorized administrative control via Unleash Protocol's multisig governance system, executes unapproved contract upgrade, and drains approximately $3.9M in WIP, USDC, WETH, stIP, and vIP tokens.","source":""},{"date":"2025-12-30","event":"PeckShieldAlert and CertiK flag the incident publicly. Attacker bridges stolen assets to Ethereum and begins depositing 1,337.1 ETH into Tornado Cash across 34 structured transactions over 11–12 hours.","source":""},{"date":"2025-12-30","event":"Unleash Protocol announces the breach on X (formerly Twitter), pauses all operations, and advises users to halt all contract interactions. States no compromise to Story Protocol infrastructure.","source":""},{"date":"2025-12-31","event":"Multiple security outlets including BleepingComputer, CoinDesk, and Coinpedia publish detailed coverage. LookonChain and Scorechain confirm governance-layer root cause.","source":""},{"date":"2026","event":"Unleash Protocol TVL recorded at $0 on DefiLlama. No user compensation or recovery timeline announced as of available reporting.","source":"","date_original":"2026-01-01"}],"sources_used":[{"url":"https://www.coindesk.com/business/2025/12/30/unleash-protocol-hit-by-usd3-9-million-exploit-with-funds-routed-through-tornado-cash","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260108083603/https://www.coindesk.com/business/2025/12/30/unleash-protocol-hit-by-usd3-9-million-exploit-with-funds-routed-through-tornado-cash","credibility":3,"archive_timestamp":"2026-01-08T08:36:03+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","name":"bleepingcomputer.com","type":"other","archive_url":"http://web.archive.org/web/20260714164637/https://www.bleepingcomputer.com/news/security/hackers-drain-39m-from-unleash-protocol-after-multisig-hijack/","credibility":3,"archive_timestamp":"2026-07-14T16:46:37+00:00"},{"url":"https://coinpedia.org/news/unleash-protocol-hack-drains-3-9m-after-multisig-exploit-peckshield-reveals/","name":"coinpedia.org","type":"other","archive_url":"http://web.archive.org/web/20260120125618/https://coinpedia.org/news/unleash-protocol-hack-drains-3-9m-after-multisig-exploit-peckshield-reveals/","credibility":3,"archive_timestamp":"2026-01-20T12:56:18+00:00"},{"url":"https://coinmarketcap.com/academy/article/unleash-protocol-loses-dollar39m-in-governance-exploit","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260307122807/https://coinmarketcap.com/academy/article/unleash-protocol-loses-dollar39m-in-governance-exploit","credibility":3,"archive_timestamp":"2026-03-07T12:28:07+00:00"},{"url":"https://www.scorechain.com/blog/unleash-protocol-incident-shows-how-governance-failures-escalate-risk","name":"scorechain.com","type":"other","archive_url":"http://web.archive.org/web/20260616061644/https://www.scorechain.com/blog/unleash-protocol-incident-shows-how-governance-failures-escalate-risk","credibility":3,"archive_timestamp":"2026-06-16T06:16:44+00:00"},{"url":"https://coinjournal.net/news/how-a-governance-failure-led-to-the-unleash-protocol-hack/","name":"coinjournal.net","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptotimes.io/2025/12/31/unleash-protocol-exploit-3-9m-stolen-via-multisig-governance-breach/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20251230200606/https://www.cryptotimes.io/2025/12/31/unleash-protocol-exploit-3-9m-stolen-via-multisig-governance-breach/","credibility":3,"archive_timestamp":"2025-12-30T20:06:06+00:00"},{"url":"https://www.cryptopolitan.com/unleash-protocol-unauthorized-withdrawals/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260122102808/https://www.cryptopolitan.com/unleash-protocol-unauthorized-withdrawals/","credibility":3,"archive_timestamp":"2026-01-22T10:28:08+00:00"},{"url":"https://defillama.com/protocol/unleash-protocol","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.unleashprotocol.xyz/others/team","name":"docs.unleashprotocol.xyz","type":"other","archive_url":"http://web.archive.org/web/20260518221750/https://docs.unleashprotocol.xyz/others/team","credibility":3,"archive_timestamp":"2026-05-18T22:17:50+00:00"},{"url":"https://bitcoinethereumnews.com/tech/unleash-protocol-exploit-causes-3-9m-loss-ip-token-dips-on-story-concerns/","name":"bitcoinethereumnews.com","type":"other","archive_url":"http://web.archive.org/web/20260829024242/https://bitcoinethereumnews.com/tech/unleash-protocol-exploit-causes-3-9m-loss-ip-token-dips-on-story-concerns/","credibility":3,"archive_timestamp":"2026-08-29T02:42:42+00:00"},{"url":"https://www.scworld.com/brief/crypto-heist-pilfers-about-3-9m-from-unleash-protocol","name":"scworld.com","type":"other","archive_url":"http://web.archive.org/web/20260102162736/https://www.scworld.com/brief/crypto-heist-pilfers-about-3-9m-from-unleash-protocol","credibility":3,"archive_timestamp":"2026-01-02T16:27:36+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:14.119561+00:00","updated_at":"2026-08-30T03:54:57.438313+00:00"}}