CrediX Faces $4.5M Exploit, Suspected Exit Scam
Details on the $4.5M exploit of CrediX, a DeFi protocol, and the suspected exit scam by its core team. Analysis of the impact and response efforts.

- CrediX DeFi project suspected in an exit scam amid $4.5M exploit.
- Core team vanished after funds drained from liquidity pools.
- Liquidity pools empty, user funds likely irrecoverable.
On August 4, 2025, DeFi lending protocol CrediX experienced a $4.5 million exploit, leading to the disappearance of its core team and raising suspicions of an exit scam.
The incident highlights ongoing vulnerabilities in DeFi protocols, impacting investor trust and emphasizing the need for strengthened security measures in the crypto industry.
CrediX $4.5M Exploit
CrediX, a DeFi lending protocol, experienced a major $4.5M exploit on August 4, 2025. Attackers accessed the protocol’s multisig admin and bridge wallets, minted unbacked tokens, and drained liquidity pools, leaving users without recourse.
The CrediX team is now suspected of an exit scam following their disappearance. All official communication channels, including website, Twitter, and Telegram, were disabled, leaving investors and users in uncertainty.
Impact and Breach Analysis
The exploit’s immediate effects were devastating with total value locked dropping to zero. This shock impacted various users and neighboring protocols tied to CrediX, affecting their operational trust and market stability.
The breach significantly undermined confidence in DeFi security protocols, emphasizing vulnerabilities related to multisig and admin wallets. The financial repercussions extend beyond affected parties to the broader ecosystem.
Investigation and Response
Current investigation focuses on the team’s identities and tracking stolen funds through blockchain analysers. Agencies have yet to release official statements, increasing industry speculation about regulatory responses and future DeFi security measures.
@CertiKAlert, Blockchain Security Firm, CertiK, “Following the incident that resulted in a $4.4M loss, the @CrediX_fi team has disappeared. X account is inactive, and the website hasn’t been brought back online since August 4.”
Historically, admin wallet compromises have resulted in rapid TVL collapses, leaving blockchain forensics and community-led networks like Stability DAO to recover assets. Increased awareness of security practices in crypto finance is anticipated.
More From Crypto News
SlowMist: Aave V3 Loop Safe Module Exploited, 114.09 ETH Stolen
Aave v3 is one of the largest decentralized lending protocols by total value locked . A module-level exploit differs from a core protocol breach, but it still c...
Ripple reveals XRPL privacy and AI-agent upgrades in Seoul
Ripple used a Seoul event to outline two new development directions for the XRP Ledger: privacy upgrades and AI-agent capabilities.
Fed Bank Reserves Fall $88.236B as Weekly Average Rises
Federal Reserve bank reserves dropped $88. 236 billion between the September 23 and September 30 Wednesday snapshots, even as the weekly average for the same pe...
Crypto Hacks Totaled $766M in September, Led by Bitget and Liquid Losses
Crypto hacks and exploits drained a reported $766 million in September, with losses tied to Bitget and Liquid exchange incidents leading the monthly tally, maki...
US Banking Group Sues OCC Over Crypto Trust Bank Approvals
A US banking industry group has filed a lawsuit against the Office of the Comptroller of the Currency, challenging the federal regulator’s decisions to approve...
20,000 ETH Moved From Bitfinex to Aave: What It Means
On-chain monitoring service Whale Alert flagged a transfer of 20,000 ETH from Bitfinex to an address attributed to Aave on Oct. 3, 2026 at 14:06:47 UTC, valuing...
