Abracadabra Faces $1.8 Million Exploit in Third Major DeFi Breach Since 2024
Abracadabra hit by $1.8M exploit, marking its third DeFi hack since 2024 and raising new concerns about protocol security.
The decentralized finance (DeFi) lending protocol Abracadabra has once again fallen victim to a significant exploit, losing approximately $1.8 million worth of Magic Internet Money (MIM)—its native decentralized stablecoin. This marks the third major breach targeting the project since early 2024, bringing cumulative losses to over $21 million.
According to blockchain security firm BlockSec Phalcon, the attacker manipulated a vulnerability within one of Abracadabra’s smart contract functions designed to verify solvency. By exploiting this flaw, the hacker managed to borrow more tokens than the provided collateral should have allowed, effectively draining 1.79 million MIM from the protocol.
The exploit occurred late Saturday night, with on-chain data revealing that the attacker funded their operation through Tornado Cash, a crypto mixer often used to obscure transaction histories. After extracting the stolen tokens, the perpetrator converted them to ETH and routed them back through Tornado Cash, complicating recovery efforts.
In a post on the project’s Discord server, Abracadabra DAO contributor 0xMerlin confirmed that the issue had been identified and contained. “A potential attack vector was identified today in some deprecated contracts. The issue has been mitigated and closed,” 0xMerlin wrote, assuring that the DAO treasury would buy back the affected MIM to stabilize the market. “No user funds have been affected.”
Abracadabra currently reports a total value locked (TVL) of roughly $154 million, with around 44 million MIM tokens circulating primarily across Ethereum and its Layer 2 network, Arbitrum.
However, this most recent attack underscores persistent security challenges within DeFi protocols—particularly those with legacy or deprecated smart contracts. Despite rapid innovation, many DeFi platforms continue to rely on earlier codebases that may not align with evolving security standards.
This latest breach follows two previous attacks:
Combined, the trio of incidents reflects over $21 million in cumulative losses, placing Abracadabra among the most frequently targeted projects in DeFi’s short but volatile history.
In response, the Abracadabra team has initiated an internal review aimed at strengthening its smart contract auditing processes and enhancing risk management. While the DAO’s swift action may reassure users, the recurring nature of these exploits raises serious questions about DeFi governance and long-term protocol resilience.
As the DeFi ecosystem continues to mature, security lapses like this one emphasize a sobering truth: even established protocols remain vulnerable when technical debt and decentralized governance collide.
- In January 2024, a similar vulnerability led to a $6.4 million loss.
- In March 2025, a more complex flash loan exploit drained another $13 million worth of MIM.



