Blockchain AcademicsBlockchain Academics
Solana DeFi Platform CrediX Exploited After Admin Access Breach, Liquidity Pool Drained

Solana DeFi Platform CrediX Exploited After Admin Access Breach, Liquidity Pool Drained

CrediX exploited after admin privileges compromised; attacker mints collateral and drains Solana-based lending pool.

Blockchain Academics NewsroomAugust 4, 20252 min read
Share

CrediX, a decentralized finance (DeFi) protocol built on Solana that specializes in tokenized private credit, suffered a major security breach this week. The exploit, discovered by blockchain security firm SlowMist, occurred after an attacker was granted admin and bridge privileges via the platform’s ACLManager, allowing them to drain the protocol’s liquidity pool.

The attacker was added to the CrediX multisig wallet six days prior to the incident, effectively gaining complete control over the lending platform’s core functionalities. In the role of Bridge, the attacker minted collateral tokens directly from the protocol, which were then used to borrow large volumes of assets, effectively stripping the platform of its liquidity.

“Credix seems to have had a security breach. We are investigating and will share details soon,” the platform stated on X (formerly Twitter) shortly after the incident was flagged.

As a precaution, CrediX has temporarily disabled its website to prevent further deposits, but emphasized that user funds remain accessible directly via smart contracts. “All user funds will be recovered in full within 24–48 hours,” the team stated, committing to swift restitution.

This incident highlights a persistent vulnerability in DeFi ecosystems: the concentration of critical permissions in multisig governance structures. Despite the decentralized promise of blockchain finance, the exploit underscores how insufficient oversight of access controls can compromise even well-funded and mission-driven platforms.

CrediX had previously secured $60 million in credit financing to support SMEs in Latin America, working in tandem with a U.S.-based alternative investment firm overseeing a $3 billion portfolio. The breach not only places its operational integrity under scrutiny, but also raises broader concerns about security standards across tokenized credit protocols.

As investigations unfold, the incident serves as a cautionary tale for DeFi protocols regarding governance frameworks, audit rigor, and the importance of early threat detection.

Discussion

Loading comments...