Skip to main content
AVOID.NET
CrediX Protocol Exit Scamreviewed 2026-09-09 · 23 claims checked

Fact-check findings

What an automated fact-checker found when it re-read CrediX Protocol Exit Scam against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #3[disputed][awaiting moderator]in section: Exploit Mechanism and Technical Details
    On approximately July 29, 2025, setup transaction 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae56e3b8e903334f35e assigned five critical roles
    reviewerThe role-grant setup transaction hash was 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae56e3b8e903334f35eTwo independent technical post-mortems (QuillAudits, Halborn) both give a transaction hash differing from the page's in one 8-character segment ('ae56e3b8e' vs 'ae72e3b8e'). The page's hash appears to be a transcription error.
    Proposed correction (not yet applied)
    On approximately July 29, 2025, setup transaction 0x0cc3520951a2b41281dcc9a0d37ef3f7f139b75675d83ae72e3b8e903334f35e assigned five critical roles
  2. #12[disputed][awaiting moderator]in section: Affected Protocols and Third-Party Response
    Stability DAO stated it was collaborating with Sonic Labs, Euler, Beets, and a protocol identified as Rines Protocol (also referred to as Trevee in some reports) to gather evidence, trace funds on-chain, and coordinate with legal and cybercrime units.
    reviewerStability DAO was collaborating with Sonic Labs, Euler, Beets, and a protocol identified as Rines Protocol (also referred to as Trevee in some reports)The collaborating-entities list is otherwise confirmed, but the parenthetical name is a one-letter transposition of the real prior name (Rings, not Rines).
    Proposed correction (not yet applied)
    Stability DAO stated it was collaborating with Sonic Labs, Euler, Beets, and a protocol identified as Rings Protocol (also referred to as Trevee in some reports) to gather evidence, trace funds on-chain, and coordinate with legal and cybercrime units.
  3. #13[disputed][awaiting moderator]in the timeline
    Stability DAO confirms collaboration with Sonic Labs, Euler, Beets, and Trevee/Rines Protocol to trace funds and coordinate with legal and cybercrime units.
    reviewerStability DAO confirms collaboration with Sonic Labs, Euler, Beets, and Trevee/Rines Protocol to trace fundsSame underlying naming error as the Overview/Affected Protocols section; grouped under the same defect_group.
    Proposed correction (not yet applied)
    Stability DAO confirms collaboration with Sonic Labs, Euler, Beets, and Trevee/Rings Protocol to trace funds and coordinate with legal and cybercrime units.
  4. #19[disputed][awaiting moderator]in section: Security Firm Findings
    CertiK maintains a Skynet project listing for the entity.
    reviewerCertiK maintains a Skynet project listing for the entity (the Sonic-based CrediX Finance)This is a real entity mix-up: the very confusion the page's own 'Note on Name Disambiguation' section warns about is reproduced in its own Security Firm Findings section, which cites the Solana project's Skynet page as if it covers the Sonic exit-scam entity.
    Proposed correction (not yet applied)
    No CertiK Skynet listing for the Sonic-based CrediX Finance entity has been identified; the skynet.certik.com/projects/credix page is a listing for the unrelated Solana-based Credix Finance protocol.
  5. #20[disputed][awaiting moderator]in the cited sources
    https://skynet.certik.com/projects/credix
    reviewersources_used entry for the CertiK Skynet page is a valid citation for this investigationSame underlying error; grouped under certik-skynet-wrong-entity.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #9[unverifiable][awaiting moderator]in the timeline
    CrediX team posts Telegram message stating the protocol was 'stolen' and pledging full recovery of all user funds within 24–48 hours, claiming a deal has been reached with the attacker.
    reviewerCrediX team posts the 'stolen'/24-48hr pledge Telegram message on August 5, 2025Could not independently pin down whether the Telegram pledge itself was posted Aug 4 or Aug 5; the cited article was published same-day as the exploit. Not confident enough to call this disputed rather than merely uncertain.
  2. #21[unverifiable][awaiting moderator]in section: Security Firm Findings
    No pre-exploit audit of the CrediX Finance protocol by a recognized third-party firm had been publicly reported, and security researchers noted the absence of bug-bounty programs or audit contests.
    reviewerNo pre-exploit audit of the CrediX Finance (Sonic) protocol by a recognized third-party firm had been publicly reported, and there were no bug-bounty programs or audit contestsPlausible (and indirectly reinforced by the fact that the only CertiK audit findable for 'credix' belongs to the unrelated Solana project — see the Skynet finding above) but not directly sourced by name in any article I could access.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #6[partially supported][awaiting moderator]in section: Exploit Mechanism and Technical Details
    Stolen funds were subsequently bridged from the Sonic network to Ethereum and distributed across three wallets. CertiK confirmed the funds remained in those Ethereum addresses and had not yet interacted with exchanges as of the initial reporting period.
    reviewerStolen funds were bridged from Sonic to Ethereum and distributed across three wallets; CertiK confirmed funds had not interacted with exchangesThe three-wallet distribution is confirmed, but the page omits QuillAudits' own finding that a portion (~300 ETH) was run through Tornado Cash, which is in tension with the 'had not yet interacted with exchanges' framing and is a notable omission given it's cited to the same technical source.
  2. #17[partially supported][awaiting moderator]in section: Broader DeFi Context
    CoinDesk reported that multisig wallet breaches were the most common attack vector in H1 2025, contributing to $3.1 billion in total crypto losses during that period.
    reviewerCoinDesk reported multisig wallet breaches were the most common attack vector in H1 2025, contributing to $3.1 billion in total crypto lossesThe $3.1B/H1-2025/multisig-as-top-vector claim is attributed on the page to CoinDesk, but CoinDesk's own reporting on the underlying Hacken data cites $2 billion, not $3.1 billion; $3.1B appears to be CoinJournal's figure. The claim is directionally accurate but the sourcing/attribution is muddled between two outlets citing different numbers for what may be different scopes or a later revision.

confirmed

11 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    CrediX Finance was a Sonic blockchain-based DeFi lending protocol that launched in July 2025 and was drained of approximately $4.5 million on August 4, 2025 following a compromise of admin wallet privileges and abuse of a BRIDGE_ROLE to mint unbacked collateral tokens.
    reviewerCrediX Finance was a Sonic-based DeFi lending protocol that launched in July 2025 and was drained of ~$4.5 million on August 4, 2025 via compromised admin privileges and BRIDGE_ROLE abuseCore summary claim is well supported by tier-1 (CoinDesk) and tier-2 (QuillAudits) reporting.
  2. #2[confirmed][no action needed]in section: Overview and Background
    Stability DAO, a Sonic-based yield protocol managing approximately $28 million in total assets, had integrated CrediX just one week prior to the exploit.
    reviewerStability DAO, managing ~$28 million in total assets, integrated CrediX one week before the exploitMatches source directly.
  3. #4[confirmed][no action needed]in section: Exploit Mechanism and Technical Details
    Using the BRIDGE_ROLE privilege, the attacker minted 2,500,000 unbacked acUSDC tokens and 3,250,000 unbacked acscUSD tokens without depositing any collateral.
    reviewerAttacker address 0xF321683831Be16eeD74dfA58b02a37483cEC662e received the five roles and minted 2,500,000 acUSDC and 3,250,000 acscUSDConfirmed against primary technical source.
  4. #5[confirmed][no action needed]in section: Exploit Mechanism and Technical Details
    approximately $2,036,501 in USDC, $1,160,000 in scUSD, $1,343,322 in wS, $55,578 in stS beets staked tokens, and $45,558 in WETH, totaling roughly $4.5 million
    reviewerStolen assets totaled roughly $4.5 million: ~$2,036,501 USDC, $1,160,000 scUSD, $1,343,322 wS, $55,578 stS, $45,558 WETHConfirmed.
  5. #7[confirmed][no action needed]in section: Exploit Mechanism and Technical Details
    Blockchain security firm SlowMist and PeckShield independently confirmed the attack vector involved compromised admin and bridge wallet access.
    reviewerSlowMist and PeckShield independently confirmed the attack vector involved compromised admin and bridge wallet accessBoth firms' involvement is independently corroborated outside the page's own cited sources.
  6. #8[confirmed][no action needed]in section: Team Disappearance and Suspected Exit Scam
    the CrediX team published a Telegram message to its approximately 1,600-member channel stating they 'deeply regret to inform you that our protocol has been stolen' and assured users that 'all user funds will be recovered in full within 24–48 hours.'
    reviewerCrediX posted a Telegram message to ~1,600 members saying the protocol was 'stolen' and pledging recovery within 24-48 hoursDirect quote match.
  7. #10[confirmed][no action needed]in section: Team Disappearance and Suspected Exit Scam
    By August 8, 2025 — four days after the exploit — blockchain security firm CertiK publicly stated that the CrediX team 'has disappeared.'
    reviewerBy August 8, 2025 CertiK publicly stated the CrediX team 'has disappeared'Confirmed by the named source and cross-corroborated.
  8. #11[confirmed][no action needed]in section: Affected Protocols and Third-Party Response
    Stability DAO team member GodInMaking publicly disclosed that the protocol held KYC documentation for two CrediX team members and was preparing a formal legal report to submit to authorities.
    reviewerStability DAO (via 'GodInMaking') disclosed it held KYC documentation on two CrediX team members and was preparing a formal legal reportConfirmed.
  9. #14[confirmed][no action needed]in section: Affected Protocols and Third-Party Response
    The compensation and recovery plan was described as requiring at least two weeks to implement.
    reviewerStability DAO's compensation and recovery plan was described as requiring at least two weeks to implementConfirmed via an independent mirror since the page's own cited MEXC URL is now dead (see link_rot finding below).
  10. #22[confirmed][no action needed]in section: Note on Name Disambiguation
    should not be confused with Credix Finance, a separate and distinct real-world asset lending protocol built on the Solana blockchain, whose founders (Thomas Bohner, Chaim Finizola, and Maxim Piessen, formerly of IntellectEU) have been publicly identified and whose operations are unrelated to the August 2025 Sonic-based incident
    reviewerThe Sonic-based CrediX entity should not be confused with the Solana-based Credix Finance, founded by Thomas Bohner, Chaim Finizola, and Maxim Piessen (formerly of IntellectEU)Confirmed; this disambiguation section is accurate, which makes it more notable that the Security Firm Findings section elsewhere conflates the same two entities via the CertiK Skynet citation.
  11. #23[confirmed][no action needed]in the timeline
    CrediX exploit executes at approximately 9:10 UTC.
    reviewerThe exploit executed at approximately 9:10 UTC on August 4, 2025Confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.