Single Attacker Drains $2M From Two Crypto Projects
An attacker exploited smart-contract flaws to steal roughly $2 million from a lending protocol and a yield aggregator, converting much of the funds into stablecoins.
A single attacker exploited vulnerabilities in two smart contracts earlier this week and moved roughly $2 million out of a decentralized lending protocol and a yield aggregator, the projects and on-chain analysts reported.
Public transaction records show funds leaving both protocols in quick succession. The stolen assets were consolidated into a small number of addresses, swapped into widely used stablecoins on decentralized exchanges and then routed through mixing services and multiple chains, according to on-chain observers.
One target was a lending protocol that lets users borrow against crypto collateral. The other was a yield aggregator that pools deposits to run automated strategies. Both teams paused key contract functions after detecting unusual outflows and posted warnings telling users to stop interacting with the affected contracts.
A project statement said investigators are working with blockchain security firms and external auditors to trace the transfers and identify the technical vector. “We are coordinating with external auditors and authorities, and we have disabled the vulnerable contract to prevent further loss,” the statement read. The other protocol reported it is reviewing recent code changes and plans to publish a postmortem once the technical review is complete.
A security researcher who examined the public transactions wrote that the attacker executed a sequence of contract calls that manipulated internal accounting, enabling withdrawals larger than allowed. “The exploit relied on a weakness in how the contracts handled state updates during complex operations,” the researcher noted. The analyst added that the attacker took steps to obscure their trail by routing funds through multiple chains and automated mixers.
On-chain investigators reported that most of the stolen value was converted into stablecoins within hours and moved through a mix of decentralized and centralized venues. Some of the funds appear to have reached services that can be used to cash out, though tracing final recipients is ongoing.
Both projects said they are considering recovery options, including asking exchanges to freeze suspect funds, using insurance reserves or treasury holdings for reimbursements, and applying technical fixes before resuming services. Users affected by the theft were urged to follow official project channels for updates and to avoid interacting with suspicious addresses.
Investigations remain active. On-chain data, coordination with exchanges and engagement with law enforcement across jurisdictions will determine whether any funds can be recovered. The two projects pledged to publish full incident reports after completing technical and legal reviews.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.






