<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Newsletter Crypto Hack</title>
    <description>Stay ahead of the latest crypto hacks &amp; security risks with our weekly newsletter. Get the latest crypto hack reports, insights &amp; analysis – all for free. Subscribe now!</description>
    
    <link>https://newslettercryptohack.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/Amszn4GLiZ.xml" rel="self"/>
    
    <lastBuildDate>Thu, 14 May 2026 19:15:22 +0000</lastBuildDate>
    <pubDate>Fri, 02 May 2025 12:48:42 +0000</pubDate>
    <atom:published>2025-05-02T12:48:42Z</atom:published>
    <atom:updated>2026-05-14T19:15:22Z</atom:updated>
    
      <category>Blockchain</category>
      <category>Cryptocurrency</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, Newsletter Crypto Hack</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/0c5f853c-6ce2-4755-8636-61a35d5ccbf3/Logo_gradient_Newsletter_Crypto_Hack.png</url>
      <title>Newsletter Crypto Hack</title>
      <link>https://newslettercryptohack.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>KiloEx: Uncovering the $7.5 Million Oracle Exploit | Newsletter Crypto Hack</title>
  <description>A Deep Dive into the $7.5 Million KiloEx Oracle Exploit, Multi-Chain Vulnerabilities, Audit Failures, and the Ongoing Search for Accountability in Decentralized Finance (DeFi)</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/819cdf21-3268-4c98-ab3c-fe09cc869402/Your_paragraph_text__15_.png" length="776067" type="image/png"/>
  <link>https://newslettercryptohack.com/p/kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack</link>
  <guid isPermaLink="true">https://newslettercryptohack.com/p/kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack</guid>
  <pubDate>Fri, 02 May 2025 12:48:42 +0000</pubDate>
  <atom:published>2025-05-02T12:48:42Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><hr class="content_break"><h1 class="heading" style="text-align:center;" id="tldr"><b>TL;DR</b></h1><p class="paragraph" style="text-align:justify;">KiloEx suffered a $7.5 million exploit due to a critical oracle access control flaw. The attacker manipulated prices across multiple chains after funding via Tornado Cash. Despite five audits, the vulnerability went undetected. KiloEx has suspended operations, filed a police report, and is pursuing recovery while addressing security concerns post-incident.</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">KiloEx, a multi-chain perpetual protocol, suffered a significant security breach resulting in a $7.5 million loss after an attacker exploited a vulnerability in its oracle system. </p><p class="paragraph" style="text-align:justify;">The attack was executed through a wallet funded via Tornado Cash, enabling the perpetrator to bypass traceability. Despite its recent expansion across Base, BNB Chain, and Taiko, the protocol failed to address a critical flaw in its oracle implementation.</p><p class="paragraph" style="text-align:justify;">The exploit did not rely on a sophisticated zero-day vulnerability; instead, it capitalized on a basic oversight, described as “the digital equivalent of walking through an unlocked front door.” </p><p class="paragraph" style="text-align:justify;">This lapse occurred shortly after the project received support from Binance, highlighting the contrast between its public milestones and internal security posture.</p><p class="paragraph" style="text-align:justify;">In the aftermath, KiloEx offered a 10% bounty to the attacker in hopes of recovering the stolen funds. The incident raises concerns about the reliability of security practices in emerging DeFi platforms. </p><p class="paragraph" style="text-align:justify;">As the original commentary noted, “having ‘Kilo’ in your name doesn’t automatically give you the heavyweight security needed in DeFi’s bloodsport arena.”</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">The security breach at KiloEx escalated rapidly, with early warnings issued by security engineer Chaofan Shou on April 14th. Shou first<a class="link" href="https://x.com/shoucccc/status/1911862514440376446?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> reported </a>that “KiloEx_perp is hacked. $6M+ loss already. Likely due to price oracle access control issues.” </p><p class="paragraph" style="text-align:justify;">Shortly thereafter, he <a class="link" href="https://x.com/shoucccc/status/1911882201211568479?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">confirmed</a> the vulnerability: “Anyone can change Kilo’s price oracle.”</p><p class="paragraph" style="text-align:justify;">Within just 20 minutes of Shou’s initial alert, Cyvers Alerts corroborated the scale of the exploit, <a class="link" href="https://x.com/CyversAlerts/status/1911867270852227131?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">announcing</a> a &quot;$7M HACK ALERT&quot; spanning multiple chains. The attack spread quickly from BNB Chain to Base and Taiko, draining funds at an alarming rate.</p><p class="paragraph" style="text-align:justify;">KiloEx<a class="link" href="https://x.com/KiloEx_perp/status/1911899600849617330?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> responded</a> hours later by suspending all platform activity and collaborating with security firms to trace the stolen funds. The incident revealed just how fragile KiloEx&#39;s security infrastructure was, particularly its oracle access controls, which allowed unrestricted manipulation of price feeds.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/KiloEx_perp/status/1911899600849617330?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:justify;">The fallout demonstrates how a single overlooked vulnerability can trigger catastrophic losses across interconnected chains, turning what should have been a robust multi-chain deployment into a liability.</p><h3 class="heading" style="text-align:justify;" id="exploit-details">Exploit Details: </h3><p class="paragraph" style="text-align:justify;">The exploit that led to KiloEx&#39;s $7.5 million loss required no advanced techniques, only a clear path through inadequate access controls. </p><p class="paragraph" style="text-align:justify;">According to an investigation by <a class="link" href="https://x.com/SlowMist_Team/status/1911991384254402737?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">SlowMist</a>, the breach stemmed from a flawed MinimalForwarder contract that failed to validate callers or verify signatures. This allowed the attacker to impersonate trusted contracts with ease.</p><p class="paragraph" style="text-align:justify;">The exploit relied on a chain of misplaced trust between four interconnected contracts: KiloPriceFeed relied on Keeper, Keeper relied on PositionKeeper, and PositionKeeper depended on MinimalForwarder. The breakdown occurred at the root, MinimalForwarder, where forged signatures and absent data validation enabled unrestricted access.</p><p class="paragraph" style="text-align:justify;">With full control of the price oracle, the attacker manipulated ETH prices at will. By first setting ETH as low as $100, opening highly leveraged long positions, then inflating prices to $10,000, they executed a rinse-and-repeat strategy to drain funds. The Base chain alone lost $3.12 million.</p><p class="paragraph" style="text-align:justify;">While <a class="link" href="https://x.com/PythNetwork?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Pyth Network</a> served as the underlying oracle provider, the breach was entirely due to KiloEx’s insecure implementation. The attacker exploited this weakness without leaving substantial traces, showcasing how insecure architecture can become a gateway for massive theft.</p><h3 class="heading" style="text-align:left;" id="tracing-the-attack">Tracing the Attack: </h3><p class="paragraph" style="text-align:justify;">The attacker behind the KiloEx exploit demonstrated a high level of coordination and preparation, beginning with the use of Tornado Cash, a well-known crypto mixer, to fund their activities. </p><p class="paragraph" style="text-align:justify;">The wallet first appeared on April 13, one day before the exploit, indicating premeditation. The originating wallet was:<br><b><a class="link" href="https://etherscan.io/tx/0xa0fa4ab8ded0c07085d244e1981919b440f78b609e1cf8d7f8ee32d358dfdf46?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xa0fa4ab8ded0c07085d244e1981919b440f78b609e1cf8d7f8ee32d358dfdf46</a></b></p><p class="paragraph" style="text-align:justify;">From there, the attacker launched synchronized attacks across Base, BNB Chain, Taiko, opBNB, and Manta, exploiting the same vulnerability on each network. The precise timing and execution reflect deliberate targeting.</p><p class="paragraph" style="text-align:justify;">All exploits were linked to the following Ethereum address:<br><b><a class="link" href="https://etherscan.io/address/0x00fac92881556a90fdb19eae9f23640b95b4bcbd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x00fac92881556a90fdb19eae9f23640b95b4bcbd</a></b></p><h3 class="heading" style="text-align:left;" id="attack-details">Attack Details:</h3><p class="paragraph" style="text-align:left;"><b>Base Chain:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Address:</b> <a class="link" href="https://basescan.org/address/0x00fac92881556a90fdb19eae9f23640b95b4bcbd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x00fac92881556a90fdb19eae9f23640b95b4bcbd</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 1 ($3.13M):</b> <a class="link" href="https://basescan.org/tx/0x6b378c84aa57097fb5845f285476e33d6832b8090d36d02fe0e1aed909228edd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x6b378c84aa57097fb5845f285476e33d6832b8090d36d02fe0e1aed909228edd</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 2 ($187k):</b> <a class="link" href="https://basescan.org/tx/0xde7f5e78ea63cbdcd199f4b109db2a551b4462dec79e4dba37711f6c814b26e6?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xde7f5e78ea63cbdcd199f4b109db2a551b4462dec79e4dba37711f6c814b26e6</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 3 ($11k):</b> <a class="link" href="https://basescan.org/tx/0xf0fcce0807a82041d050a60461e187f0e81a6f7fbda69bb600c04049d924e138?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xf0fcce0807a82041d050a60461e187f0e81a6f7fbda69bb600c04049d924e138</a></p></li></ul><p class="paragraph" style="text-align:left;"><b>BNB Chain:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Address:</b> <a class="link" href="https://bscscan.com/address/0x00fac92881556a90fdb19eae9f23640b95b4bcbd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x00fac92881556a90fdb19eae9f23640b95b4bcbd</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 1 ($893k):</b> <a class="link" href="https://bscscan.com/tx/0x1aaf5d1dc3cd07feb5530fbd6aa09d48b02cbd232f78a40c6ce8e12c55927d03?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x1aaf5d1dc3cd07feb5530fbd6aa09d48b02cbd232f78a40c6ce8e12c55927d03</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 2 ($10k):</b> <a class="link" href="https://bscscan.com/tx/0x38b25be14b83fd549d5e0b29ba962db83d41f5f9072d0eac4f692fa8e7110bc0?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x38b25be14b83fd549d5e0b29ba962db83d41f5f9072d0eac4f692fa8e7110bc0</a></p></li></ul><p class="paragraph" style="text-align:left;"><b>opBNB:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Address:</b> <a class="link" href="https://opbnbscan.com/address/0x00fac92881556a90fdb19eae9f23640b95b4bcbd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x00fac92881556a90fdb19eae9f23640b95b4bcbd</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 1 ($2.9M):</b> <a class="link" href="https://opbnbscan.com/tx/0x79eb28ae21698733048e2dae9f9fe3d913396dc9d93a0e30d659df6065127964?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x79eb28ae21698733048e2dae9f9fe3d913396dc9d93a0e30d659df6065127964</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 2 ($205.5k):</b> <a class="link" href="https://opbnbscan.com/tx/0xcfc679a66f1d2966dbe83bb827409c40f29f881c20128107ae73e93ab55c65e4?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xcfc679a66f1d2966dbe83bb827409c40f29f881c20128107ae73e93ab55c65e4</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction 3 ($14k):</b> <a class="link" href="https://opbnbscan.com/tx/0x783d56ce53af6d59c7c4be374ff48a66257733fadf5905526b5862a54917889f?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x783d56ce53af6d59c7c4be374ff48a66257733fadf5905526b5862a54917889f</a></p></li></ul><p class="paragraph" style="text-align:left;"><b>Taiko:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Address:</b> <a class="link" href="https://taikoscan.io/address/0x00fac92881556a90fdb19eae9f23640b95b4bcbd?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack#asset-multichain" target="_blank" rel="noopener noreferrer nofollow">0x00faC92881556A90FdB19eAe9F23640B95B4bcBd</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction ($41k):</b> <a class="link" href="https://taikoscan.io/tx/0x9bce6e105cea138fe9fb1e4bfb63fe90d21817db9d2cc6d1bf7697317430215b?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x9bce6e105cea138fe9fb1e4bfb63fe90d21817db9d2cc6d1bf7697317430215b</a></p></li></ul><p class="paragraph" style="text-align:left;"><b>Manta:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>Address:</b><a class="link" href="https://pacific-explorer.manta.network/address/0x551f3110f12c763D1611d5A63B5F015d1c1a954C?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> 0xd43b395efad4877e94e06b980f4ed05367484bf3</a></p></li><li><p class="paragraph" style="text-align:left;"><b>Transaction ($100k):</b> <a class="link" href="https://pacific-explorer.manta.network/tx/0x06074831103a1e91c7b6dcb3b641cf4b79bfa208ea75e99cf9b5100d60a82df5?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x06074831103a1e91c7b6dcb3b641cf4b79bfa208ea75e99cf9b5100d60a82df5</a></p></li></ul><p class="paragraph" style="text-align:justify;">The attacker also used a separate Ethereum address to bridge funds:<br><b><a class="link" href="https://etherscan.io/address/0x551f3110f12c763d1611d5a63b5f015d1c1a954c?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x551f3110f12c763D1611d5A63B5F015d1c1a954C</a></b></p><p class="paragraph" style="text-align:justify;">In total, the amount stolen is estimated at approximately <b>$7,491,500</b>.</p><p class="paragraph" style="text-align:justify;">By the time SlowMist’s MistTrack flagged the attacker’s addresses, the stolen funds were already being moved across various blockchain bridges, including zkBridge, deBridge, and Meson. </p><p class="paragraph" style="text-align:justify;">These once-promising cross-chain protocols, intended to enhance DeFi&#39;s borderless potential, now served as ideal avenues for the attacker to launder the stolen funds.</p><p class="paragraph" style="text-align:justify;">In <a class="link" href="https://x.com/KiloEx_perp/status/1911899600849617330?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">response</a>, KiloEx quickly urged &quot;all partner protocols and platforms to blacklist this address&quot; while working with security partners to track the flow of the stolen assets. This is becoming a common response in the DeFi space, where security breaches have become an unfortunately predictable pattern.</p><p class="paragraph" style="text-align:justify;">In such a severe security violation, what more can a platform do beyond sending a strongly worded request to the blockchain?</p><h3 class="heading" style="text-align:justify;" id="consequences">Consequences:</h3><p class="paragraph" style="text-align:justify;">KiloEx’s response to the attack came swiftly, but it followed the familiar steps seen in many DeFi hacks: suspend trading, blacklist addresses, and trace the stolen funds. This reaction, while necessary, was akin to locking the door after the burglars had already made off with the loot.</p><p class="paragraph" style="text-align:justify;">The following day, the platform<a class="link" href="https://x.com/KiloEx_perp/status/1912131572750582236?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> announced </a>that the vulnerability had been identified and would be fixed soon, a revelation that seemed more like a formality than a breakthrough, after all, the damage had already been done.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/KiloEx_perp/status/1912131572750582236?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:justify;">It was like discovering the front door was broken after the valuables were taken.</p><p class="paragraph" style="text-align:justify;">The platform then made its<a class="link" href="https://x.com/KiloEx_perp/status/1912080346063282651?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> offer to the hacker</a>: return 90% of the $7.5 million, keep 10% as a &quot;whitehat bounty,&quot; and KiloEx would even send out a tweet acknowledging the cooperation. The message, however, felt more like a desperate plea than a genuine negotiation.</p><p class="paragraph" style="text-align:justify;">Their statement, dripping with an air of desperation masked as strength, read: &quot;Our investigation, supported by law enforcement, cybersecurity agencies, and multiple exchanges & bridge protocols, has uncovered critical information about your activities.&quot;</p><p class="paragraph" style="text-align:justify;">KiloEx’s plea to the attacker could be summarized simply: return the funds. However, the attacker has remained silent, with their wallets still untouched and holding the full $7.5 million in stolen assets.</p><p class="paragraph" style="text-align:justify;">In response, KiloEx has <a class="link" href="https://x.com/KiloEx_perp/status/1912850992653283655?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">filed a police report</a> in Hong Kong and stated they are cooperating with the Criminal Division, Cybercrime Unit, and cybersecurity firm SlowMist. The platform is freezing positions based on pre-attack snapshots and has promised user compensation plans, while also attempting direct on-chain communication with the attacker.</p><p class="paragraph" style="text-align:justify;">Curiously, KiloEx took the opportunity to <a class="link" href="https://x.com/KiloEx_perp/status/1912850992653283655?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">address</a> “rumors suggesting KiloEx may have been involved in the hack,” despite the fact that such suspicions were not prominent until the platform brought them up. This move has raised questions about whether they unintentionally invited speculation about an insider threat.</p><p class="paragraph" style="text-align:justify;">KiloEx confirmed that they had undergone<a class="link" href="https://docs.kiloex.io/kiloex/about-kiloex/audit?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> five audits</a> since June 2023. However, these assessments failed to prevent the exploit. </p><p class="paragraph" style="text-align:justify;">The most recent audit, conducted by ScaleBit in <a class="link" href="https://scalebit.xyz/reports/20250321-XKilo-Token-Final-Audit-Report.pdf?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">March 2025</a>, offered a response that <a class="link" href="https://x.com/scalebit_/status/1912025236654215435?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">sidestepped responsibility</a>. The firm stated they were “deeply saddened” by the incident but noted that “the root cause falls outside the scope of our audit.”</p><p class="paragraph" style="text-align:justify;">This raises critical concerns about audit standards. If a security audit does not account for vulnerabilities in something as fundamental as Oracle access control, what exactly is its purpose?</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">KiloEx now joins the long list of protocols brought down by oracle manipulation, a classic vulnerability that continues to exploit the DeFi space&#39;s weakest links.</p><p class="paragraph" style="text-align:justify;">Despite deploying on Base, BNB Chain, Taiko, and opBNB, KiloEx left its MinimalForwarder completely exposed, giving attackers direct access to $7.5 million in user funds. This was not a sophisticated hack, just a basic failure in access control that could have been prevented.</p><p class="paragraph" style="text-align:justify;">The team prioritized expansion over security, and it showed. Five audits since June 2023 failed to catch the flaw that ultimately drained the protocol. The result was a sprawling multi-chain rollout built on a compromised foundation.</p><p class="paragraph" style="text-align:justify;">Users are not interested in retroactive fixes or apologetic audit statements. They care about protocols that take security seriously from day one. When your MinimalForwarder becomes the doorway to a full treasury drain, no amount of post-mortem analysis or PR cleanup will restore trust.</p><p class="paragraph" style="text-align:center;">Thank you for reading our latest Crypto Hack story.<br>Like, Subscribe and Share for more crypto hack content below.</p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://newslettercryptohack.com/subscribe?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=kiloex-uncovering-the-7-5-million-oracle-exploit-newsletter-crypto-hack"><span class="button__text" style=""> Subscribe </span></a></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d9788090-bb63-4625-8e97-5d1705049521&utm_medium=post_rss&utm_source=newsletter_crypto_hack">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>PancakeSwap: Controversy Over veCAKE Governance Shift | Newsletter Crypto Hack</title>
  <description>PancakeSwap Faces Backlash Over Tokenomics Proposal as veCAKE Holders and DeFi Builders Accuse Protocol of Centralization, Governance Manipulation, and Betrayal of Long-Term Commitments.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/938fc925-2002-4b4d-9fb9-e0929c9d2cdc/Your_paragraph_text__14_.png" length="316908" type="image/png"/>
  <link>https://newslettercryptohack.com/p/pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack</link>
  <guid isPermaLink="true">https://newslettercryptohack.com/p/pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack</guid>
  <pubDate>Fri, 02 May 2025 12:43:33 +0000</pubDate>
  <atom:published>2025-05-02T12:43:33Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><hr class="content_break"><h1 class="heading" style="text-align:center;" id="tldr"><b>TL;DR</b></h1><p class="paragraph" style="text-align:justify;">PancakeSwap’s proposal to retire the veCAKE model sparked significant backlash from the community. Critics cited governance centralization, suspicious large-scale CAKE lockups, and weakened token utility. Despite community-suggested alternatives, the team pushed forward. The debate underscores broader concerns about DeFi governance integrity and the centralization risks within protocol-led tokenomic changes.</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">On April 8, 2025, PancakeSwap unveiled its latest governance overhaul — &quot;<a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Tokenomics Proposal 3.0</a>&quot; — promising &quot;True Ownership.&quot; However, this proposal has triggered concerns across the DeFi community, as it seeks to dismantle veCAKE, the very system that once empowered long-term token holders with governance influence.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/PancakeSwap/status/1909532322388754754?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">What’s causing alarm isn’t just the proposal itself, but the timing and mechanics surrounding it. In the days leading up to the vote, <a class="link" href="https://x.com/Cakepiexyz_io/status/1910424625349353752?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">several wallet addresses locked</a> in close to 50% of the total CAKE supply, effectively positioning themselves to control the outcome. </p><p class="paragraph" style="text-align:left;">This massive accumulation raises serious questions about decentralization and whether PancakeSwap’s governance model is being undermined from within.</p><p class="paragraph" style="text-align:left;">Projects deeply integrated into PancakeSwap’s ecosystem now face an uncertain future. Notably, <a class="link" href="https://x.com/Cakepiexyz_io?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Cakepie</a> — a protocol that locked around 13 million CAKE via a liquid staking wrapper — could be rendered obsolete. These wrappers allow users to stake long-term without losing liquidity, mirroring the model used by <a class="link" href="https://www.convexfinance.com/?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Convex on Curve</a>.</p><p class="paragraph" style="text-align:left;">Ironically, those building innovative tools to strengthen PancakeSwap’s long-term growth may now be the first casualties of its so-called evolution. As the platform shifts toward a streamlined governance model, builders are left questioning whether DeFi’s promise of permissionless innovation is being replaced by centralized decision-making masked as progress.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">The <a class="link" href="https://www.defiwars.xyz/wars/pancake?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">governance landscape</a> at PancakeSwap has entered a volatile new chapter. </p><p class="paragraph" style="text-align:left;">With <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Tokenomics Proposal 3.0</a>, the protocol is targeting the elimination of veCAKE, a core mechanism designed to safeguard the protocol from whale manipulation and give long-term stakers real influence. Yet, the proposal arrived without any prior consultation with stakeholders or warnings issued to the builders most affected by it.</p><p class="paragraph" style="text-align:left;">Adding fuel to the fire, just before the proposal was revealed, a newly active wallet locked a<a class="link" href="https://x.com/Cakepiexyz_io/status/1910424625349353752?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> massive amount of CAKE</a>, strategically split across multiple fresh addresses. </p><p class="paragraph" style="text-align:left;">This sudden move positioned the holder to significantly sway the outcome of the proposal. In stark contrast to long-term veCAKE stakers who committed for years, these newly minted “governance mercenaries” could exit the system immediately once the vote passes.</p><p class="paragraph" style="text-align:left;">This power play threatens not just token holders but entire ecosystems. Cakepie, which has approximately<a class="link" href="https://www.defiwars.xyz/wars/pancake?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> 13 million CAKE </a>locked via its liquid staking wrapper, is now staring down a potential collapse — a protocol-ending risk for a team that built on the assumption of long-term governance stability.</p><p class="paragraph" style="text-align:left;">PancakeSwap <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">frames</a> the move as a push toward “flexibility” and “sustainable growth.” But the timing of the wallet activity, the absence of community dialogue, and the systematic removal of governance rights paint a far more troubling picture.</p><p class="paragraph" style="text-align:left;">With the vote yet to begin, tension is rising and backlash is intensifying. If governance itself becomes the battlefield, the question remains: is this evolution — or a hostile takeover?</p><h3 class="heading" style="text-align:left;" id="mercenary-voting-a-threat-to-govern">Mercenary Voting: A Threat to Governance Integrity</h3><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://docs.pancakeswap.finance/earn/cake-staking/vecake?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">PancakeSwap’s veCAKE model</a></b><b> was built on a foundational principle: governance power should be earned through long-term commitment, not short-term opportunism. </b></p><p class="paragraph" style="text-align:left;">By locking CAKE for extended periods, users weren’t just rewarded with yield — they were entrusted with influence, symbolizing alignment with the protocol’s long-term vision.</p><p class="paragraph" style="text-align:left;">But that principle is now under siege.</p><p class="paragraph" style="text-align:left;">In the days leading up to the Tokenomics Proposal 3.0, a <a class="link" href="https://x.com/Cakepiexyz_io/status/1910424625349353752?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">single address locked</a> nearly 50% of the <a class="link" href="https://www.defiwars.xyz/wars/pancake?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">entire CAKE supply</a> distributed across multiple fresh wallets, a move likely designed to evade scrutiny. </p><p class="paragraph" style="text-align:left;">This sudden concentration of power contradicts the very spirit of veCAKE, introducing what many are calling a “mercenary voter” into the system.</p><p class="paragraph" style="text-align:left;">The address in question — <a class="link" href="https://bscscan.com/address/0xd183f2bbf8b28d9fec8367cb06fe72b88778c86b?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xd183f2bbf8b28d9fec8367cb06fe72b88778c86b</a> — has raised significant red flags. On-chain <a class="link" href="https://x.com/juapia/status/1910333191853924358?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">analysis conducted by Juapia</a>, a long-time PancakeSwap ambassador, traced this wallet back to a more alarming source. </p><p class="paragraph" style="text-align:left;">Its first transaction came from:<br><a class="link" href="https://bscscan.com/address/0x655e2488e1f116be4020dc37aebf9895e074c33e?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x655E2488E1f116bE4020DC37AEbf9895e074c33E</a></p><p class="paragraph" style="text-align:left;">A suspicious transfer linked to transaction:<br><a class="link" href="https://bscscan.com/tx/0xedd0305fa4d8941be31aa3b69d36d05c514262b1092dc876da3763a879a7764f?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0xedd0305fa4d8941be31aa3b69d36d05c514262b1092dc876da3763a879a7764f</a><br><br>— which itself was originally funded by a <a class="link" href="https://x.com/PancakeSwap/status/1317031179258716160?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">known PancakeSwap treasury wallet</a>:<br><a class="link" href="https://bscscan.com/address/0x7122c91049511b58a14ce2ce10f1acf318cc51d0?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">0x7122C91049511b58A14Ce2CE10f1aCF318cc51d0</a>.</p><p class="paragraph" style="text-align:left;">This link was confirmed via a historic post from PancakeSwap, identifying the treasury address as legitimate.</p><p class="paragraph" style="text-align:left;">Juapia <a class="link" href="https://x.com/juapia/status/1910333191853924358?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">sounded the alarm</a>: “It is not a simple whale.” The evidence suggests this <a class="link" href="https://x.com/PancakeSwap/status/1317031179258716160?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">wallet</a> may be acting with privileged insight or insider alignment, and is now poised to become the decisive voting bloc capable of dismantling veCAKE.</p><p class="paragraph" style="text-align:left;">Perhaps the most concerning aspect: if Proposal 3.0 passes, the locked tokens behind this governance blitz could be immediately unlocked — allowing the orchestrator to exit with zero repercussions, while the rest of the community deals with the fallout.</p><p class="paragraph" style="text-align:left;">This episode underscores a chilling reality: when the rules of governance themselves can be rewritten through governance, the door opens to manipulation by those who can afford to buy control.</p><h3 class="heading" style="text-align:left;" id="collateral-damage-builders-left-in-">Collateral Damage: Builders Left in the Dark</h3><p class="paragraph" style="text-align:left;">Cakepie didn’t expect to become the cautionary tale for decentralized governance. Yet, in the wake of PancakeSwap’s Tokenomics Proposal 3.0, that’s exactly what has happened.</p><p class="paragraph" style="text-align:left;">For over a year, Cakepie has been the largest veCAKE holder, locking 13 million CAKE for four years — not for speculation, but to build infrastructure, drive liquidity, and enhance yield strategies for PancakeSwap users. </p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/cakepiexyz_io/status/1909870534277341347?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.cakepiexyz.io/cakepie-overview?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Their model </a>mirrors <a class="link" href="https://www.convexfinance.com/?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Convex’s relationship with Curve</a>: users deposit CAKE and receive mCAKE, a liquid alternative, while Cakepie’s CKP token handles the governance layer. The outcome was a win-win — liquidity for users, directional influence for the protocol.</p><p class="paragraph" style="text-align:left;">That carefully built model now stands on the edge of collapse.</p><p class="paragraph" style="text-align:left;">“We were blindsided,” <a class="link" href="https://x.com/cakepiexyz_io/status/1909870534277341347?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Cakepie said after learning about the proposal</a> with the rest of the community. “After our continuous support and consistent contributions, this abrupt shift feels deeply misaligned with the mutual trust we’ve worked hard to establish.”</p><p class="paragraph" style="text-align:left;">Dondon, a leading figure at Cakepie,<a class="link" href="https://x.com/dondon_crypto/status/1909812826236944622?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> was more direct</a>: “The big PancakeSwap mistake is happening. They built a protocol based on freedom to create, and now they’re pulling the rug on the very builders they empowered. Is this DeFi? No. This is betrayal.”</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/stakedaohq/status/1909918698086809848?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Stake DAO</a>, another key ecosystem participant, finds itself in a similar bind. With more than $500,000 locked through their sdCAKE system, the team now questions the direction PancakeSwap is heading. They voiced “deep concerns” about a proposal that “goes in the opposite direction from PancakeSwap’s development over the past year.”</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/stakedaohq/status/1909918698086809848?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">Stake DAO has<a class="link" href="https://x.com/stakedaohq/status/1909918698086809848?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> called</a> on PancakeSwap’s core contributors — referred to as “the Kitchen” — to reconsider the proposal entirely or, at minimum, offer a fair compensation framework to affected parties.</p><p class="paragraph" style="text-align:left;">These aren’t just passive investors. They’re protocol-layer builders who committed both capital and development resources based on PancakeSwap’s invitation to build atop veCAKE. They didn’t gamble — they aligned long-term, exactly as the system asked.</p><p class="paragraph" style="text-align:left;">Now, with the rules changing overnight, those very commitments are being punished.</p><p class="paragraph" style="text-align:left;">The proposal promises “<a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">True Ownership</a>,” but raises an uncomfortable question: ownership of what? A token stripped of its governance rights? A “community-focused” protocol that just sidelined its most loyal contributors?</p><p class="paragraph" style="text-align:left;">Even <a class="link" href="https://x.com/newmichwill/status/1909678061202944035?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Michael Egorov</a>, the architect behind Curve Finance’s ve-tokenomics model, weighed in with a stark warning: “ve-tokenomics reason to exist is to prevent governance attacks, making decision makers take long-term responsibility over their actions… Upgradability is a bug. Don’t make your veGovernance upgradable, especially the lock part.”</p><p class="paragraph" style="text-align:left;">In crypto, the ethos has always been that code is law, and long-term alignment deserves reward. But when a DAO changes fundamental rules without warning, the very idea of decentralization comes under threat.</p><h3 class="heading" style="text-align:left;" id="deflationary-growth-or-governance-g">Deflationary Growth or Governance Gutting?</h3><p class="paragraph" style="text-align:left;">Tokenomics Proposal 3.0 arrives wrapped in glossy language — &quot;flexibility,&quot; &quot;sustainability,&quot; &quot;long-term success.&quot; But beneath the surface, it reads more like a systematic dismantling of PancakeSwap’s existing governance structure.</p><p class="paragraph" style="text-align:left;">A closer examination strips away the euphemisms.</p><p class="paragraph" style="text-align:left;">The proposal states that <i>“veCAKE and Gauges Voting System will be retired.”</i> In plain terms, those who locked CAKE for years, based on the promise of governance power, will lose that voice entirely. Long-term alignment, the cornerstone of ve-tokenomics, would be rendered meaningless.</p><p class="paragraph" style="text-align:left;">It continues: <i>“All staked CAKE will be unlocked with no penalties.”</i> On the surface, this might sound fair. But in practice, it grants exit liquidity to short-term actors while undercutting those who committed to the ecosystem for years, especially protocols that built their models around long-term staking.</p><p class="paragraph" style="text-align:left;">Then there&#39;s <i>“reducing emissions from ~40,000 CAKE to ~22,250 CAKE per day.”</i> This sounds like a move toward deflation, but without clarity on distribution, it&#39;s simply fewer rewards, likely funneled through centralized channels.</p><p class="paragraph" style="text-align:left;">More striking is the removal of core utility: <i>“Future IFO and TGE participation will not require CAKE staking.”</i> This move strips away one of the last incentives for locking CAKE, effectively transforming the token from a governance and utility asset into a passive instrument.</p><p class="paragraph" style="text-align:left;">And finally, the most concerning line: <i>“The PancakeSwap team will directly manage emissions” using “real-time data.”</i> In effect, the Kitchen team replaces decentralized decision-making with centralized control, undermining the entire premise of token-holder governance.</p><p class="paragraph" style="text-align:left;">Forum <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/15?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">contributor AtuIA summarized</a> it clearly: <i>“So what exactly is this Tokenomics 3.0? From what I read, 95% of the content focuses on removing the old tokenomics model. Meanwhile, the part about the new tokenomics is either vaguely mentioned as ‘easier and more efficient’ or not mentioned at all... Isn’t this like wanting to tear down the old house immediately while having no clear design or preparation for the new one?”</i></p><p class="paragraph" style="text-align:left;">The proposal claims progress, but it offers no clear plan for what comes next. Removing the foundation risks toppling the entire structure that PancakeSwap’s community helped build.</p><h3 class="heading" style="text-align:left;" id="gamified-tokenomics-or-centralized-">Gamified Tokenomics or Centralized Cleanup?</h3><p class="paragraph" style="text-align:left;">The PancakeSwap team argues that the veCAKE system has become “too complex” and that it “allocates rewards inefficiently.” At a glance, this critique is somewhat true.</p><p class="paragraph" style="text-align:left;">Prior to the controversial CAKE lock-up, protocols like Cakepie had amassed close to 50% of all voting power. </p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/defiwars_/status/1909955378168684553?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">By leveraging this influence, they <a class="link" href="https://x.com/2lambro/status/1909784441775702213?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">directed a significant share of emissions toward pools</a> that often lacked sufficient trading volume, extracting more value than they arguably generated.</p><p class="paragraph" style="text-align:left;">Head Chef Philip<a class="link" href="https://x.com/0xchefphilip/status/1910092870239007049?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> put it bluntly</a>: <i>“Numbers never lie. Some pools extract value from $CAKE holders without adding much value.”</i></p><p class="paragraph" style="text-align:left;">But instead of refining the system — implementing emission caps, tightening efficiency metrics, or enforcing penalties for underperformance — PancakeSwap chose a scorched-earth response: eliminate veCAKE entirely.</p><p class="paragraph" style="text-align:left;">Prominent voices in the community have pushed back.<a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/5?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> Hubert, a long-time contributor</a>, pointed out the overreaction: <i>“The solution is not to deprecate the very good veCAKE model... Just stop giving 25% of emissions to Magpie.”</i></p><p class="paragraph" style="text-align:left;">Kuwada <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/28?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">echoed</a> concerns about PancakeSwap&#39;s long-term credibility: <i>“If PancakeSwap releases v4 next, will there be any promising projects willing to build on it, trusting PCS again? With Uniswap available, why would anyone choose PCS?”</i></p><p class="paragraph" style="text-align:left;">Reasonable alternatives existed: <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/5?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">caps on emissions</a> for low-efficiency pools, realigned <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/10?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">incentives that reward volume</a>, not just influence, and <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/46?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">exit options with penalties</a> to discourage mercenary governance.</p><p class="paragraph" style="text-align:left;">Yet the community’s suggestions were sidelined. The result? A “solution” that solves inefficiency by replacing decentralization with centralized control.</p><p class="paragraph" style="text-align:left;">The message rings clear: when tokenomics are gamed, PancakeSwap’s fix isn’t dialogue or design iteration — it’s complete structural overhaul, with power consolidated at the core.</p><p class="paragraph" style="text-align:left;">Is this a response to inefficiency, or a rebrand of centralization dressed in the language of reform?</p><h3 class="heading" style="text-align:left;" id="the-kitchens-defense-or-strategic-s">The Kitchen’s Defense or Strategic Silence?</h3><p class="paragraph" style="text-align:left;">Amid growing backlash, PancakeSwap <a class="link" href="https://blog.pancakeswap.finance/articles/forum-feedback-cake-tokenomics-3-0-discussion-proposal?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">released a blog post</a> addressing community concerns, or at least appearing to. </p><p class="paragraph" style="text-align:left;">The<a class="link" href="https://blog.pancakeswap.finance/articles/forum-feedback-cake-tokenomics-3-0-discussion-proposal?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> post answered nine curated questions</a> but conspicuously avoided the one issue at the heart of the controversy: the massive and sudden CAKE lock-up that now dominates voting power.</p><p class="paragraph" style="text-align:left;">On Twitter, PancakeSwap’s Head Chef<a class="link" href="https://x.com/Headchef_pcs/status/1910319463435813156?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> offered a vague reassurance</a>: <i>“We’re happy to see CAKE community members actively participating in the ecosystem,”</i> referring to the newly locked CAKE. But the statement ignored the suspicious origins of those addresses, leaving a deeper question unresolved: who’s actually behind the vote?</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/Headchef_pcs/status/1910319463435813156?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">Critics were quick to respond. <i>“Given that half the user base faces geo-restrictions from participating in the TGE, how can PancakeSwap claim to be truly decentralized?”</i> asked community member <a class="link" href="https://x.com/marcopolo2027/status/1909881689238553023?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Marco Polo</a>. </p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://blog.pancakeswap.finance/articles/forum-feedback-cake-tokenomics-3-0-discussion-proposal?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">reply </a>that the TGE is merely a Binance Wallet partnership and IFOs will become “more accessible” felt like sidestepping rather than accountability.</p><p class="paragraph" style="text-align:left;">Even when asked whether veCAKE would remain active during the vote,<a class="link" href="https://blog.pancakeswap.finance/articles/forum-feedback-cake-tokenomics-3-0-discussion-proposal?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> the answer was a simple “yes”</a> — effectively cementing the influence of the sudden whale wallets without investigation.</p><p class="paragraph" style="text-align:left;">Technical clarifications fared no better. The blog admitted the 4% annual deflation target wasn’t guaranteed — it was based on past trading volume and could easily miss its mark if conditions changed. Meanwhile, community proposals offering balanced alternatives like capped emissions and penalty-based exits were acknowledged, then summarily ignored.</p><p class="paragraph" style="text-align:left;">When the only official response to allegations of governance manipulation is a controlled FAQ that dodges the core issue, it raises a sobering question:</p><p class="paragraph" style="text-align:left;">Is this decentralized governance — or just centralized control wrapped in the language of community?</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Governance wars don’t spill blood, but they do erode trust. PancakeSwap now stands at a crossroads: uphold its decentralized foundation or continue down a path that concentrates control in the hands of a few.</p><p class="paragraph" style="text-align:left;">So far, the team appears to be choosing the latter. Carefully worded proposals and FAQ pages are doing little to obscure the reality laid bare on-chain: a coordinated lock-up of nearly half the veCAKE supply by newly activated wallets, timed precisely to influence a proposal that would eliminate veCAKE’s very premise, long-term commitment.</p><p class="paragraph" style="text-align:left;">Grimmace from Cakepie <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/68?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">summed it up succinctly</a>: <i>“Kitchen’s goal is for CAKE deflation and improved reward efficiency. Cakepie is definitely glad to help, and I believe this could be done through different mechanisms rather than just killing veCAKE directly.”</i></p><p class="paragraph" style="text-align:left;">If price stability is the primary concern, why inject 79 million unlocked CAKE into circulation while dismantling the lock-in mechanism designed to reduce sell pressure? As user <a class="link" href="https://forum.pancakeswap.finance/t/cake-tokenomics-proposal-3-0-true-ownership-simplified-governance-and-sustainable-growth/1237/45?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Bethoveen noted</a>, <i>“Burns alone cannot keep up with this influx, not in the short term nor over several years.”</i></p><p class="paragraph" style="text-align:left;">Community sentiment offers no ambiguity. According to Marco Polo’s tally, roughly 75% of unique users criticized the proposal, while fewer than 20% voiced support. His question cuts to the heart of the matter: <i>“Was this community discussion meant to listen, or just a box to tick off while a quiet 25M vote block waits in the shadows to force approval?”</i></p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/marcopolo2027/status/1910186923164836085?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">Michael Egorov’s<a class="link" href="https://x.com/newmichwill/status/1909678061202944035?s=46&utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow"> reminder</a> resonates across the DeFi landscape: <i>“Upgradability is a bug”</i> when applied to governance commitments. His symbolic move to <a class="link" href="https://etherscan.io/tx/0x0daf3451ab32979f5a8a1876a51b3cab23aff0ceeb0f8dbbe8163658ad50ed72?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">re-lock all veCRV </a>positions for four years offers a stark contrast to PancakeSwap’s current trajectory.</p><p class="paragraph" style="text-align:left;">Importantly, this remains a proposal, not yet policy. There is still room to recalibrate. PancakeSwap has the opportunity to respond to the overwhelming community feedback, engage meaningfully with ecosystem stakeholders, and design a governance model that balances long-term sustainability with fair representation.</p><p class="paragraph" style="text-align:left;">The broader takeaway is clear: in DeFi, governance is only as resilient as its ability to resist manipulation by those closest to the controls.</p><p class="paragraph" style="text-align:left;">This proposal might yet become a turning point, a reminder that decentralization must be defended, not just declared. And in the strong, unified pushback from the community, there is a glimmer of hope that the next era of DeFi governance will be shaped not by quiet consolidations of power, but by the conviction of those who still believe in its founding ideals.</p><p class="paragraph" style="text-align:center;">Thank you for reading our latest Crypto Hack story.<br>Like, Subscribe and Share for more crypto hack content below.</p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://newslettercryptohack.com/subscribe?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=pancakeswap-controversy-over-vecake-governance-shift-newsletter-crypto-hack"><span class="button__text" style=""> Subscribe </span></a></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=0c0f446b-9d74-4be8-8e4f-b7c061fd384e&utm_medium=post_rss&utm_source=newsletter_crypto_hack">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>UPCX Hack: $70 Million Stolen in Smart Contract Exploit | Newsletter Crypto Hack</title>
  <description>UPCX suffers $70 million loss after smart contract exploit, prompting token price drop and raising concerns over access control vulnerabilities in Web3.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f9fb81cf-155b-4a01-88df-0c6e814305fd/Your_paragraph_text__17_.png" length="799553" type="image/png"/>
  <link>https://newslettercryptohack.com/p/upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack</link>
  <guid isPermaLink="true">https://newslettercryptohack.com/p/upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack</guid>
  <pubDate>Fri, 02 May 2025 12:28:39 +0000</pubDate>
  <atom:published>2025-05-02T12:28:39Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><hr class="content_break"><h1 class="heading" style="text-align:center;" id="tldr"><b>TL;DR</b></h1><p class="paragraph" style="text-align:justify;">UPCX suffered a $70 million exploit after an attacker gained unauthorized access and upgraded its ProxyAdmin contract, draining funds from management accounts. The platform suspended operations and confirmed user assets remain safe. UPC’s token fell 7%, and investigations continue as experts link the breach to weak access controls and admin privileges.</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">A serious security breach has rocked UPCX, an open-source payment platform, resulting in the loss of approximately $70 million worth of digital assets. The incident, confirmed through a security alert on April 1, involved unauthorized access that enabled a malicious actor to withdraw millions in tokens.</p><p class="paragraph" style="text-align:justify;">The blockchain security firm <a class="link" href="https://x.com/CyversAlerts/status/1907046941906653633?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">Cyvers</a> was among the first to flag the suspicious activity, identifying a total of 18.4 million UPC tokens being moved. According to their assessment, the total value of the compromised funds is estimated at $70 million.</p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/CyversAlerts/status/1907046941906653633?utm_source=cryptohackalert.com&utm_medium=newsletter&utm_campaign=upcx-hack-70-million-stolen-in-smart-contract-exploit&_bhlid=d2849c9e29ed9fbde9cf5c770dc56dafef818409"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:justify;">Investigations reveal that the attacker gained control of a UPCX address and proceeded to upgrade its ProxyAdmin contract. This change gave them administrative privileges, which were then used to trigger a withdrawal function. As a result, funds were drained from three separate management accounts.</p><p class="paragraph" style="text-align:justify;">At the time of reporting, the stolen tokens have not yet been exchanged for other cryptocurrencies, leaving their next move uncertain. UPCX has temporarily halted its operations as internal investigations are underway, and the team has not yet issued an official statement in response to inquiries.</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">Following the breach, UPCX <a class="link" href="https://x.com/Upcxofficial/status/1907024397497749647?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack" target="_blank" rel="noopener noreferrer nofollow">confirmed</a> that it had identified &quot;unauthorized activity&quot; impacting its internal management accounts. In response, the platform immediately suspended all deposits and withdrawals to prevent further damage. </p><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/Upcxofficial/status/1907024397497749647?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:justify;">The team reassured users that their personal assets remained secure and unaffected by the incident, while also emphasizing that a full investigation is currently in progress.</p><p class="paragraph" style="text-align:justify;">The market reacted swiftly to the news. According to data from CoinGecko, the price of UPC’s token declined by 7%, dropping from a high of $4.06 to a low of $3.77 during the period of the exploit.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ac37baff-386c-403e-b4cc-a752395de652/image.png?t=1744176878"/><div class="image__source"><span class="image__source_text"><p>Coingecko</p></span></div></div><p class="paragraph" style="text-align:justify;">Blockchain security firm Cyvers continues to monitor the situation closely. In a statement to Cointelegraph, Meir Dolev, co-founder and chief technology officer at Cyvers, noted that the specific method used in the attack is still under investigation. </p><p class="paragraph" style="text-align:justify;">However, he pointed out that similar incidents in the past have commonly been linked to compromised credentials or weaknesses in access control systems.</p><p class="paragraph" style="text-align:justify;">Dolev highlighted that such vulnerabilities have been the leading cause of Web3-related financial losses in 2024, contributing to over 80% of the funds stolen this year. </p><p class="paragraph" style="text-align:justify;">He explained that the attack on UPCX follows a familiar pattern, where unauthorized access to core administrative privileges is used to initiate malicious contract upgrades and siphon funds.</p><p class="paragraph" style="text-align:justify;">“This incident mirrors attack patterns we’ve documented in prior exploits, where access to critical administrative roles enabled malicious upgrades and fund drainage,” Dolev said.</p><p class="paragraph" style="text-align:justify;">The breach has reignited concerns about smart contract security across the crypto space. Dolev stressed the importance of strengthening protections around wallet permissions, implementing robust multisignature solutions, and enforcing real-time transaction validation. </p><p class="paragraph" style="text-align:justify;">With $70 million lost in this single incident, April’s total already surpasses the $33 million stolen throughout March.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/126a0093-542b-453c-bf14-f66c7270de51/image.png?t=1744177349"/><div class="image__source"><span class="image__source_text"><p>Total Hack losses in March by PeckShield</p></span></div></div><p class="paragraph" style="text-align:justify;">The escalating trend in Web3 exploits raises pressing questions about how platforms can reinforce their defenses moving forward.</p><hr class="content_break"><p class="paragraph" style="text-align:justify;">The UPCX breach reminds us of ongoing security challenges in the Web3 space. Although the platform acted quickly to contain the damage and assured users their assets were safe, the $70 million loss and 7% drop in token value reflect a serious hit to user confidence.</p><p class="paragraph" style="text-align:justify;">As investigations continue, the incident highlights the urgent need for stronger access controls, better wallet permission systems, and more robust multisig security. UPCX’s response and recovery will not only shape its future but also influence how the broader industry addresses smart contract vulnerabilities moving forward.</p><p class="paragraph" style="text-align:center;">Thank you for reading our latest Crypto Hack story.<br>Like, Subscribe and Share for more crypto hack content below.</p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://newslettercryptohack.com/subscribe?utm_source=newslettercryptohack.com&utm_medium=newsletter&utm_campaign=upcx-hack-70-million-stolen-in-smart-contract-exploit-newsletter-crypto-hack"><span class="button__text" style=""> Subscribe </span></a></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b985a15b-334d-4d43-848b-ce49d227b000&utm_medium=post_rss&utm_source=newsletter_crypto_hack">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
