⚠️UNLEASH PROTOCOL HACKED FOR 3.9M$
Unleash Protocol suffered a governance exploit worth 3.9M$ after a multisig flaw in Story. The stolen funds were transferred to Ethereum and sent via Tornado Cash.
⚠️UNLEASH PROTOCOL HACKED FOR 3.9M$
Unleash Protocol suffered a governance exploit worth 3.9M$ after a multisig flaw in Story. The stolen funds were transferred to Ethereum and sent via Tornado Cash.
. @UnleashProtocol, a DeFi platform for intellectual property (IP) management and money market operations built on @StoryProtocol, reported unauthorized activity in its smart contracts.
An external address gained administrative control through the protocol's multisig governance mechanism and performed an unapproved contract upgrade. This allowed the unauthorized withdrawal of user funds.
Affected assets include:
• WIP
• USDC
• WETH
• stIP
• vIP
The stolen funds were subsequently bridged to @ethereum and partially laundered, with approximately 1,337 ETH (part of the ~$3.9 million total loss) deposited into @TornadoCash.
The incident is isolated to Unleash Protocol's own governance and contracts. There is no evidence of any compromise to Story Protocol's core L1 infrastructure, validators, or contracts. Losses are estimated at around $3.9 million.
Current Status
Unleash Protocol has paused all operations and is conducting a full investigation with independent security experts and forensic analysts.
User
According to Wu, Unleash Protocol issued an announcement stating that its smart contracts experienced unauthorized activity, resulting in user funds being withdrawn and transferred. Preliminary investigation shows that an external address obtained managerial rights through Unleash's multisignature governance mechanism and performed an unauthorized contract upgrade, thereby triggering unapproved asset extraction. The assets confirmed to be affected currently include WIP, USDC, WETH, stIP, and vIP. The related assets were subsequently transferred to an external address via third‑party cross‑chain infrastructure. Unleash indicated that the incident stemmed from its own governance and permission framework, and there is no evidence that Story Protocol's contracts, validators, or underlying infrastructure were impacted; the scope of impact appears limited to Unleash‑related contracts and managerial permissions. All protocol operations have now been halted. https://t.co/58SUejmX85
PeckShieldAlert 发推称,部署在 Story 上的 Unleash Protocol 发生未授权资金被盗事件,造成约 390 万美元损失。攻击者随后将被盗资金跨链转至 Ethereum,并将其中 1,337.1 枚 ETH 存入 Tornado Cash。