← CrediX Protocol Exit Scam1 decision on this page
Audit log
Every state-changing event for CrediX Protocol Exit Scam: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-31 23:21:06ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
5LZgX1E5Ssqv…7b42nP42sha256 → base58
verifying row…canonical bytes (20358 B) ▸
{"actor":"system:backfill","investigation_id":"17bbcf97-bc64-48ce-b4df-ec30114a0548","kind":"publish","page_slug":"credix-protocol-exit-scam","published_at":"2026-07-31T23:21:06.644Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"CrediX Protocol Exit Scam","sections":[{"content":"CrediX Finance operated as a real-world asset lending protocol on the Sonic blockchain. The protocol launched in July 2025, less than one month before the exploit. It offered lending and borrowing functionality backed by off-chain income and DeFi collateral. Stability DAO, a Sonic-based yield protocol managing approximately $28 million in total assets, had integrated CrediX just one week prior to the exploit. The protocol's rapid launch, brief operational period, and the sequence of events following the exploit have led observers to categorize it as a suspected exit scam rather than a purely external security breach.","heading":"Overview and Background","severity":"critical","sources":[{"credibility":1,"name":"DeFi Protocol CrediX Hit by $4.5M Exploit, Taken Offline — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit"},{"credibility":2,"name":"CrediX Finance Faces 4.5M Exploit (Exit Scam Analysis) — QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"}]},{"content":"The exploit was executed through a multi-step privilege escalation that began six days before the funds were drained. On approximately July 29, 2025, setup transaction 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae56e3b8e903334f35e assigned five critical roles — POOL_ADMIN_ROLE, BRIDGE_ROLE, ASSET_LISTING_ADMIN_ROLE, EMERGENCY_ADMIN_ROLE, and RISK_ADMIN_ROLE — to attacker address 0xF321683831Be16eeD74dfA58b02a37483cEC662e through CrediX's ACLManager contract at 0x8f0431f6adb3e81d282d0508c16e2817dc95095b. The allegedly compromised admin EOA is 0x0dd010513F7abB8F9c628dC164a24D953BCA09Cf. Using the BRIDGE_ROLE privilege, the attacker minted 2,500,000 unbacked acUSDC tokens and 3,250,000 unbacked acscUSD tokens without depositing any collateral. These worthless synthetic tokens were then used as collateral to borrow legitimate on-chain assets: approximately $2,036,501 in USDC, $1,160,000 in scUSD, $1,343,322 in wS, $55,578 in stS beets staked tokens, and $45,558 in WETH, totaling roughly $4.5 million. Stolen funds were subsequently bridged from the Sonic network to Ethereum and distributed across three wallets. CertiK confirmed the funds remained in those Ethereum addresses and had not yet interacted with exchanges as of the initial reporting period. Blockchain security firm SlowMist and PeckShield independently confirmed the attack vector involved compromised admin and bridge wallet access.","heading":"Exploit Mechanism and Technical Details","severity":"critical","sources":[{"credibility":2,"name":"CrediX Finance Faces 4.5M Exploit (Exit Scam Analysis) — QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"},{"credibility":2,"name":"CrediX Finance hacked for $4.5m via governance flaw — Crypto.news","type":"news_article","url":"https://crypto.news/credix-finance-hacked-for-4-5m-via-governance-flaw/"},{"credibility":2,"name":"CertiK: CrediX Has Disappeared Following Multi-Million Dollar Hack — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/certik-credix-has-disappeared-following-multi-million-dollar-hack/"},{"credibility":2,"name":"CrediX hack adds to $3.1 billion DeFi losses in 2025 — CoinJournal","type":"news_article","url":"https://coinjournal.net/news/credix-hack-adds-to-3-1-billion-defi-losses-in-2025-as-multisig-failures-surge/"}]},{"content":"Immediately following the August 4, 2025 exploit, the CrediX team published a Telegram message to its approximately 1,600-member channel stating they 'deeply regret to inform you that our protocol has been stolen' and assured users that 'all user funds will be recovered in full within 24–48 hours.' The team further alleged they had negotiated a recovery deal with the attacker involving a treasury payout and token airdrop. No such recovery materialized. By August 8, 2025 — four days after the exploit — blockchain security firm CertiK publicly stated that the CrediX team 'has disappeared.' The protocol's official X account was rendered inactive, the project website was taken offline, and the Telegram channel was deleted. No post-exploit communication from the team has since emerged. The pattern — a brief operational window, a large and technically sophisticated drain of funds, a public promise of repayment, and subsequent erasure of all team presence — is widely characterized by security researchers and affected protocols as consistent with an exit scam in which the exploit was allegedly used as cover for deliberate fund extraction.","heading":"Team Disappearance and Suspected Exit Scam","severity":"critical","sources":[{"credibility":1,"name":"CrediX team vanishes after $4.5 million exploit, deletes socials and takes website offline — The Block","type":"news_article","url":"https://www.theblock.co/post/366159/credix-team-vanishes-after-4-5-million-exploit-deletes-socials-and-takes-website-offline"},{"credibility":1,"name":"CrediX Team Vanishes as Stability DAO Preps Legal Report — Decrypt","type":"news_article","url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report"},{"credibility":2,"name":"CrediX Team Vanishes After $4.5M Exploit in Suspected DeFi Exit Scam — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/credix-team-vanishes-4-5m-124135338.html"},{"credibility":2,"name":"Exit Scam? DeFi Protocol CrediX's Team Vanishes Following $4.5 Million Exploit — Mitrade","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-1026010-20250809"}]},{"content":"Several DeFi protocols and organizations reported material losses as a result of the CrediX exploit. Stability DAO, which had integrated CrediX one week before the exploit, was among the most heavily affected. Stability DAO team member GodInMaking publicly disclosed that the protocol held KYC documentation for two CrediX team members and was preparing a formal legal report to submit to authorities. Stability DAO stated it was collaborating with Sonic Labs, Euler, Beets, and a protocol identified as Rines Protocol (also referred to as Trevee in some reports) to gather evidence, trace funds on-chain, and coordinate with legal and cybercrime units. The compensation and recovery plan was described as requiring at least two weeks to implement. Stability DAO also engaged specialized firms for on-chain fund tracing. As of reporting, no recovery or prosecution outcome had been confirmed.","heading":"Affected Protocols and Third-Party Response","severity":"high","sources":[{"credibility":1,"name":"CrediX Team Vanishes as Stability DAO Preps Legal Report — Decrypt","type":"news_article","url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report"},{"credibility":2,"name":"CrediX Team Vanishes as Stability DAO Preps Legal Report — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/credix-team-vanishes-stability-dao-171634828.html"},{"credibility":2,"name":"Stability DAO: Funds affected by the CrediX attack, report being prepared — MEXC News","type":"news_article","url":"https://www.mexc.com/news/stability-dao-funds-affected-by-the-credix-attack-and-a-report-is-being-prepared-to-recover-funds/64473"},{"credibility":2,"name":"CrediX Finance Vanishes After $4.5M Hack, Stability DAO Steps In — CoinTribune","type":"news_article","url":"https://www.cointribune.com/en/credix-finance-disappears-4-5m-hack/"}]},{"content":"Multiple blockchain security firms investigated the incident. CertiK confirmed the $4.5 million loss, identified the CrediX team as having disappeared, and published three Ethereum wallet addresses holding the stolen funds, noting they had not interacted with exchanges. SlowMist independently confirmed the attacker gained access to the protocol's multisig admin and bridge wallets six days before the exploit. QuillAudits published a detailed technical post-mortem identifying the specific contract addresses, privilege roles assigned, and token minting amounts. The incident was also noted by PeckShield. No pre-exploit audit of the CrediX Finance protocol by a recognized third-party firm had been publicly reported, and security researchers noted the absence of bug-bounty programs or audit contests. CertiK maintains a Skynet project listing for the entity. The admin access compromise bore hallmarks consistent with an insider event, given that the privilege grants occurred six days prior to the drain — suggesting either a compromised team member or deliberate orchestration by insiders.","heading":"Security Firm Findings","severity":"critical","sources":[{"credibility":2,"name":"CrediX Finance Faces 4.5M Exploit (Exit Scam Analysis) — QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"},{"credibility":2,"name":"CREDIX Finance — CertiK Skynet Project Insight","type":"research","url":"https://skynet.certik.com/projects/credix"},{"credibility":2,"name":"CrediX Finance hacked for $4.5m via governance flaw — Crypto.news","type":"news_article","url":"https://crypto.news/credix-finance-hacked-for-4-5m-via-governance-flaw/"}]},{"content":"The CrediX incident occurred within a broader wave of multisig and admin-key compromise incidents in 2025. CoinDesk reported that multisig wallet breaches were the most common attack vector in H1 2025, contributing to $3.1 billion in total crypto losses during that period. The CrediX case is notable for the six-day lag between privilege assignment and fund drainage, which security researchers have highlighted as a potential indicator of deliberate insider action rather than an opportunistic external hack. The pattern of a short-lived protocol, concentrated admin control, rapid fund extraction, and team disappearance is consistent with documented exit scam archetypes in DeFi.","heading":"Broader DeFi Context","severity":"high","sources":[{"credibility":2,"name":"CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge — CoinJournal","type":"news_article","url":"https://coinjournal.net/news/credix-hack-adds-to-3-1-billion-defi-losses-in-2025-as-multisig-failures-surge/"},{"credibility":1,"name":"DeFi Protocol CrediX Hit by $4.5M Exploit, Taken Offline — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit"},{"credibility":2,"name":"CrediX Incident Uncovers Alarming Exit Scam Vulnerabilities in DeFi — OneSafe Blog","type":"research","url":"https://www.onesafe.io/blog/credix-exit-scam-vulnerabilities-defi"}]},{"content":"The entity under investigation — CrediX Finance or CrediX Protocol, operating on the Sonic blockchain — should not be confused with Credix Finance, a separate and distinct real-world asset lending protocol built on the Solana blockchain, whose founders (Thomas Bohner, Chaim Finizola, and Maxim Piessen, formerly of IntellectEU) have been publicly identified and whose operations are unrelated to the August 2025 Sonic-based incident. The naming similarity has caused confusion in some reports. This investigation concerns only the Sonic-based CrediX entity involved in the August 2025 exploit.","heading":"Note on Name Disambiguation","severity":"low","sources":[{"credibility":2,"name":"Credix Finance on Solana: Project Review — Solana Compass","type":"other","url":"https://solanacompass.com/projects/credix-finance"},{"credibility":1,"name":"CrediX pledges full reimbursement after $4.5 million DeFi exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit"}]}],"sources_used":[{"credibility":1,"name":"DeFi Protocol CrediX Hit by $4.5M Exploit, Taken Offline — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit"},{"credibility":1,"name":"CrediX pledges full reimbursement after $4.5 million DeFi exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit"},{"credibility":1,"name":"CrediX team vanishes after $4.5 million exploit, deletes socials and takes website offline — The Block","type":"news_article","url":"https://www.theblock.co/post/366159/credix-team-vanishes-after-4-5-million-exploit-deletes-socials-and-takes-website-offline"},{"credibility":1,"name":"CrediX Team Vanishes as Stability DAO Preps Legal Report — Decrypt","type":"news_article","url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report"},{"credibility":2,"name":"CrediX Team Vanishes After $4.5M Exploit in Suspected DeFi Exit Scam — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/credix-team-vanishes-4-5m-124135338.html"},{"credibility":2,"name":"CrediX Finance Faces 4.5M Exploit (Exit Scam Analysis) — QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"},{"credibility":2,"name":"CrediX Finance's $4.5M Exploit — QuillAudits Medium","type":"research","url":"https://quillaudits.medium.com/credix-finances-4-5m-exploit-96526a5119cc"},{"credibility":2,"name":"CertiK: CrediX Has Disappeared Following Multi-Million Dollar Hack — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/certik-credix-has-disappeared-following-multi-million-dollar-hack/"},{"credibility":2,"name":"CrediX Finance hacked for $4.5m via governance flaw — Crypto.news","type":"news_article","url":"https://crypto.news/credix-finance-hacked-for-4-5m-via-governance-flaw/"},{"credibility":2,"name":"CrediX Finance Team Suspected of Exit Scam After $4.5 Million Hack — AInvest","type":"news_article","url":"https://www.ainvest.com/news/credix-finance-team-suspected-exit-scam-4-5-million-hack-2508/"},{"credibility":2,"name":"CrediX hack adds to $3.1 billion DeFi losses in 2025 as multisig failures surge — CoinJournal","type":"news_article","url":"https://coinjournal.net/news/credix-hack-adds-to-3-1-billion-defi-losses-in-2025-as-multisig-failures-surge/"},{"credibility":2,"name":"CrediX Finance Vanishes After $4.5M Hack, Stability DAO Steps In — CoinTribune","type":"news_article","url":"https://www.cointribune.com/en/credix-finance-disappears-4-5m-hack/"},{"credibility":2,"name":"CREDIX Finance — CertiK Skynet Project Insight","type":"research","url":"https://skynet.certik.com/projects/credix"},{"credibility":2,"name":"CrediX DeFi Protocol Loses $4.5 Million in Admin Access Attack — Brave New Coin","type":"news_article","url":"https://bravenewcoin.com/insights/credix-defi-protocol-loses-4-5-million-in-admin-access-attack"},{"credibility":2,"name":"DeFi Project CrediX Allegedly Rug Pulls After $4.5 Million Hack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/credix-defi-exit-scam-after-hack/"},{"credibility":2,"name":"CrediX Rugpull? Team Vanishes After $4.5 Million Exploit — Coinspeaker","type":"news_article","url":"https://www.coinspeaker.com/credix-rugpull-team-vanishes-after-4-5-million-exploit/"},{"credibility":2,"name":"CrediX Team Suspectedly Pulls Off Exit Scam After $4.5M Hack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2025/08/08/credix-team-suspectedly-pulls-off-exit-scam-after-4-5m-hack/"},{"credibility":2,"name":"Exit Scam? DeFi Protocol CrediX's Team Vanishes — Mitrade","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-1026010-20250809"},{"credibility":2,"name":"Stability DAO: Funds affected by the CrediX attack — MEXC News","type":"news_article","url":"https://www.mexc.com/news/stability-dao-funds-affected-by-the-credix-attack-and-a-report-is-being-prepared-to-recover-funds/64473"},{"credibility":2,"name":"CrediX Shuts Down Social Media After $4.5M DeFi Exploit — AInvest","type":"news_article","url":"https://www.ainvest.com/news/credix-shuts-social-media-4-5m-defi-exploit-prompts-exit-scam-fears-2508/"},{"credibility":2,"name":"CrediX Finance Team Vanishes After $4.5M Hack, Exit Scam Suspected — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/credix-finance-team-vanishes-after-4-5m-hack-exit-scam-suspected/"},{"credibility":2,"name":"CrediX Incident Uncovers Alarming Exit Scam Vulnerabilities in DeFi — OneSafe Blog","type":"research","url":"https://www.onesafe.io/blog/credix-exit-scam-vulnerabilities-defi"}],"summary":"CrediX Finance was a Sonic blockchain-based DeFi lending protocol that launched in July 2025 and was drained of approximately $4.5 million on August 4, 2025 following a compromise of admin wallet privileges and abuse of a BRIDGE_ROLE to mint unbacked collateral tokens. Within days of the exploit, the team deleted its X account, took the website offline, and abandoned its Telegram channel — having previously promised full user reimbursement within 24–48 hours — leading multiple blockchain security firms and affected protocols to characterize the event as a suspected exit scam.","timeline":[{"date":"2025-07-01","event":"CrediX Finance launches on the Sonic blockchain as a DeFi lending protocol, less than one month before the exploit.","source":"QuillAudits Hack Analysis","source_url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"},{"date":"2025-07-29","event":"Approximately six days before the exploit, setup transaction 0x0cc352... assigns five critical admin and bridge roles to attacker address 0xF321683831Be16eeD74dfA58b02a37483cEC662e via the ACLManager contract.","source":"QuillAudits Hack Analysis","source_url":"https://www.quillaudits.com/blog/hack-analysis/credix-finance-4.5m-exploit"},{"date":"2025-07-29","event":"Stability DAO integrates CrediX into its Metavault product, one week before the exploit.","source":"Decrypt","source_url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report"},{"date":"2025-08-04","event":"CrediX exploit executes at approximately 9:10 UTC. Attacker mints 2.5 million unbacked acUSDC and 3.25 million unbacked acscUSD, borrows approximately $4.5 million in real assets, and bridges funds from Sonic to Ethereum. Website is taken offline.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/08/04/defi-protocol-credix-taken-offline-after-usd4-5m-exploit"},{"date":"2025-08-05","event":"CrediX team posts Telegram message stating the protocol was 'stolen' and pledging full recovery of all user funds within 24–48 hours, claiming a deal has been reached with the attacker.","source":"The Block","source_url":"https://www.theblock.co/post/365458/solana-lender-credix-defi-exploit"},{"date":"2025-08-06","event":"Final known communication from the CrediX team via Telegram.","source":"Decrypt","source_url":"https://decrypt.co/334313/credix-team-vanishes-stability-dao-preps-legal-report"},{"date":"2025-08-08","event":"CertiK publicly states the CrediX team 'has disappeared,' with the X account inactive and the website offline for four consecutive days. Stability DAO discloses it holds KYC information for two CrediX team members and is preparing a formal legal report for authorities.","source":"Crypto Economy / Decrypt","source_url":"https://crypto-economy.com/certik-credix-has-disappeared-following-multi-million-dollar-hack/"},{"date":"2025-08-08","event":"Stability DAO confirms collaboration with Sonic Labs, Euler, Beets, and Trevee/Rines Protocol to trace funds and coordinate with legal and cybercrime units.","source":"Yahoo Finance","source_url":"https://finance.yahoo.com/news/credix-team-vanishes-stability-dao-171634828.html"},{"date":"2025-08-09","event":"Multiple outlets including Mitrade, BeInCrypto, Coinspeaker, and CryptoTimes publish analyses characterizing the incident as a probable exit scam. No further communication from the CrediX team is recorded.","source":"BeInCrypto","source_url":"https://beincrypto.com/credix-defi-exit-scam-after-hack/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 451dceeb-be92-46dd-a7f1-83738a697f0f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.