HomeSecurityHackers stole $3.9 million from Unleash Protocol

Hackers stole $3.9 million from Unleash Protocol

Decentralized intellectual property platform Unleash Protocol lost approximately $3.9 million in cryptocurrency when an unauthorized contract upgrade occurred that allowed for fund withdrawals.

See also: Vulnerability in Apache StreamPipes could lead to complete control by hackers

Unleash Protocol
Hackers stole $3.9 million from Unleash Protocol

According to the blockchain project team, the attacker gained sufficient signing privileges to act as an administrator in Unleash's multisig governance system.

“Our initial investigation indicates that an external address gained administrative control through Unleash’s multisig governance mechanism and proceeded with an unauthorized contract upgrade,” the company said in a public statement.

Unleash Protocol is presented as an operating system for managing intellectual property, converting it into on-chain assets (tokens), which can be used as collateral in the DeFi ecosystem.

The platform also offers a level of commercial exploitation through smart contracts, automatically distributing revenue from licenses and royalties to pre-defined beneficiaries, based on rules recorded on the blockchain.

Through the unauthorized upgrade, the perpetrator gained the ability to withdraw and removed assets such as WIP (wrapped IP), USDC, WETH (wrapped Ether), stIP (staked IP) , and vIP (voting-escrowed IP).

See also: Cybercrime: Hackers are more organized than IT

Hackers stole $3.9 million from Unleash Protocol

Blockchain security experts from PeckShieldAlert estimate the total loss at around $3.9 million. After the withdrawals, the funds were transferred through third-party infrastructure and sent to external addresses, making them harder to trace.

Finally, PeckShieldAlert reports that the attacker deposited the stolen funds into the cryptocurrency mixing service Tornado Cash, in the form of 1,337 ETH.

The Tornado Cash service, which was placed under US sanctions in 2022 and delisted in 2025 due to its involvement in money laundering on behalf of North Korean hacking groups, allows users to funnel cryptocurrencies through obfuscation mechanisms before withdrawing them to new wallets that cannot be easily associated.

Although it was designed to provide privacy for transactions on public blockchains, it has been repeatedly abused by cybercriminals to evade authorities' surveillance and asset freezing.

In response to the incident, Unleash Protocol suspended operations and initiated an investigation in collaboration with external security experts to identify the root cause of the attack. At the same time, remediation and fund recovery measures are being considered.

See also: Chinese hackers use rootkit to hide ToneShell

Hackers stole $3.9 million from Unleash Protocol

Until there is an official announcement from the company's official channels that the use of the platform is safe again, users are urged not to interact with Unleash Protocol contracts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS