Abracadabra Finance has confirmed a safety exploit affecting its gmCauldron sensible contracts, ensuing within the theft of roughly $13 million and is taking steps to recuperate the funds.
The protocol has since disabled borrowing throughout all cauldrons and is working with blockchain safety corporations to trace the stolen funds, based on an organization assertion.
The assault, which blockchain safety agency PeckShield first flagged, focused the combination between GMX decentralized change and Abracadabra’s lending contracts.
“The total harm of the assault is presently being assessed. We’re working along with Guardian Audits, GMX, and different safety friends to establish the execution of the hack,” the corporate posted.
Abracadabra famous that its gmCauldrons underwent audits by Guardian Audits earlier than deployment and have been built-in into a number of safety monitoring programs — together with Zeroshadow monitoring and Hexagate response software program. Regardless of these measures, the breach was solely detected after the attacker executed a number of transactions.
The Zeroshadow group finally alerted Abracadabra, prompting a direct shutdown of all borrowing capabilities.
Blockchain analytics agency Chainalysis has been enlisted to trace the stolen property, which have been bridged from Arbitrum (ARB) to Ethereum (ETH) and consolidated into no less than three addresses.
Abracadabra is providing the attacker a 20% bug bounty to return the remaining funds, stating:
“To the hacker, we’re blissful to entertain negotiations for a bug bounty of 20% of the full. Attain out at [email protected] or on-chain to our treasury deal with on ETH 0xDF2C270f610Dc35d8fFDA5B453E74db5471E126B.”
A full autopsy of the most recent exploit can be launched as soon as the investigation is full, the corporate stated.


