CrediX Protocol Exit Scam
Summary
CrediX Finance was a Sonic blockchain-based DeFi lending protocol that launched in July 2025 and was drained of approximately $4.5 million on August 4, 2025 following a compromise of admin wallet privileges and abuse of a BRIDGE_ROLE to mint unbacked collateral tokens. Within days of the exploit, the team deleted its X account, took the website offline, and abandoned its Telegram channel — having previously promised full user reimbursement within 24–48 hours — leading multiple blockchain security firms and affected protocols to characterize the event as a suspected exit scam.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2025-07-01
CrediX Finance launches on the Sonic blockchain as a DeFi lending protocol, less than one month before the exploit.
QuillAudits Hack Analysis2025-07-29
Approximately six days before the exploit, setup transaction 0x0cc352... assigns five critical admin and bridge roles to attacker address 0xF321683831Be16eeD74dfA58b02a37483cEC662e via the ACLManager contract.
QuillAudits Hack Analysis2025-07-29
Stability DAO integrates CrediX into its Metavault product, one week before the exploit.
Decrypt2025-08-04
CrediX exploit executes at approximately 9:10 UTC. Attacker mints 2.5 million unbacked acUSDC and 3.25 million unbacked acscUSD, borrows approximately $4.5 million in real assets, and bridges funds from Sonic to Ethereum. Website is taken offline.
CoinDesk2025-08-05
CrediX team posts Telegram message stating the protocol was 'stolen' and pledging full recovery of all user funds within 24–48 hours, claiming a deal has been reached with the attacker.
The Block2025-08-08
CertiK publicly states the CrediX team 'has disappeared,' with the X account inactive and the website offline for four consecutive days. Stability DAO discloses it holds KYC information for two CrediX team members and is preparing a formal legal report for authorities.
Crypto Economy / Decrypt2025-08-08
Stability DAO confirms collaboration with Sonic Labs, Euler, Beets, and Trevee/Rines Protocol to trace funds and coordinate with legal and cybercrime units.
Yahoo Finance2025-08-09
Multiple outlets including Mitrade, BeInCrypto, Coinspeaker, and CryptoTimes publish analyses characterizing the incident as a probable exit scam. No further communication from the CrediX team is recorded.
BeInCryptoDecision Log
- #1publish⛓ pending7/31/2026, 11:21:06 PMhash: 5LZgX1E5SsqvH4NUt7GU1s3Y38Q2TEbsxTdR7b42nP42
21 of 22 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/31/2026, 11:21:01 PM
last updated: 8/1/2026, 8:56:08 AM
avoid.net — verified advice for a post-truth world