An unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affectedAn unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affected

How a governance failure led to the Unleash Protocol hack

  • An unauthorised contract upgrade enabled direct withdrawals from the protocol.
  • Funds were bridged to Ethereum and laundered through Tornado Cash.
  • Assets affected included WIP, USDC, WETH, stIP, and vIP.

A governance failure at Unleash Protocol has resulted in a major security breach, with attackers draining around $3.9 million in user funds.

The incident was first identified by blockchain security firm PeckShieldAlert and later confirmed by the Unleash team.

While the exploit did not affect the wider Story ecosystem, it has renewed attention on how governance mechanisms can become a critical point of failure in decentralised finance.

Unleash Protocol is a decentralised platform built on Story Protocol.

The project said the incident was limited to its own contracts and administrative controls, with no signs of compromise across Story Protocol’s validators or core infrastructure.

Even so, the event shows how vulnerabilities at the application level can still lead to significant losses.

Governance controls bypassed

On-chain analysis indicates the attacker targeted Unleash Protocol’s multi-signature governance system.

By exploiting weaknesses in how admin permissions were enforced, the attacker gained unauthorised access normally reserved for approved signers.

This access was then used to push through a contract upgrade that had not been sanctioned by the core team.

The unauthorised upgrade altered how the protocol handled withdrawals. With standard governance checks effectively bypassed, the attacker was able to move funds directly out of the protocol.

According to Unleash, these actions occurred outside its established governance framework and were not detected until after the funds had already been removed.

Laundering through bridges and mixers

After extracting the assets, the attacker bridged the funds to Ethereum. From there, the assets were broken into multiple transactions, a strategy often used to make tracking more difficult.

Blockchain data shows that 1,337.1 ETH was later deposited into Tornado Cash. The deposits were made in varying sizes, ranging from small transfers to batches of up to 100 ETH.

This pattern suggests a deliberate attempt to obscure transaction trails and reduce the effectiveness of on-chain monitoring tools.

Tokens impacted

In an official incident notice, Unleash Protocol confirmed that several assets were affected during the exploit.

These included WIP, USDC, WETH, stIP, and vIP.

The team reiterated that all affected withdrawals took place through the unauthorised contract upgrade rather than through normal user interactions.

The clarification that Story Protocol itself was not compromised is significant.

It indicates that the breach stemmed from Unleash’s internal governance design, not from flaws in the underlying blockchain or its validator set.

Emergency measures taken

Following confirmation of the breach, Unleash Protocol paused all platform operations to prevent further losses.

The team said it is working with independent security experts and forensic investigators to determine how the governance safeguards were bypassed and whether additional vulnerabilities remain.

Users have been advised to avoid interacting with Unleash Protocol contracts until further updates are issued.

The project has stated that future communications will be shared only through official channels as the investigation continues.

The post How a governance failure led to the Unleash Protocol hack appeared first on CoinJournal.

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.0007
$1.0007$1.0007
-0.01%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Share
BitcoinEthereumNews2025/09/18 00:56
Why losing THIS support could drag XRP toward $1

Why losing THIS support could drag XRP toward $1

The post Why losing THIS support could drag XRP toward $1 appeared on BitcoinEthereumNews.com. Rising activity clashes with weakening momentum as XRP price struggles
Share
BitcoinEthereumNews2025/12/31 03:24
Curve Finance votes on revenue-sharing model for CRV holders

Curve Finance votes on revenue-sharing model for CRV holders

The post Curve Finance votes on revenue-sharing model for CRV holders appeared on BitcoinEthereumNews.com. Curve Finance has proposed a new protocol called Yield Basis that would share revenue directly with CRV holders, marking a shift from one-off incentives to sustainable income. Summary Curve Finance has put forward a revenue-sharing protocol to give CRV holders sustainable income beyond emissions and fees. The plan would mint $60M in crvUSD to seed three Bitcoin liquidity pools (WBTC, cbBTC, tBTC), with 35–65% of revenue distributed to veCRV stakers. The DAO vote runs from up to Sept. 24, with the proposal seen as a major step to strengthen CRV tokenomics after past liquidity and governance challenges. Curve Finance founder Michael Egorov has introduced a proposal to give CRV token holders a more direct way to earn income, launching a system called Yield Basis that aims to turn the governance token into a sustainable, yield-bearing asset.  The proposal has been published on the Curve DAO (CRV) governance forum, with voting open until Sept. 24. A new model for CRV rewards Yield Basis is designed to distribute transparent and consistent returns to CRV holders who lock their tokens for veCRV governance rights. Unlike past incentive programs, which relied heavily on airdrops and emissions, the protocol channels income from Bitcoin-focused liquidity pools directly back to token holders. To start, Curve would mint $60 million worth of crvUSD, its over-collateralized stablecoin, with proceeds allocated across three pools — WBTC, cbBTC, and tBTC — each capped at $10 million. 25% of Yield Basis tokens would be reserved for the Curve ecosystem, and between 35% and 65% of Yield Basis’s revenue would be given to veCRV holders. By emphasizing Bitcoin (BTC) liquidity and offering yields without the short-term loss risks associated with automated market makers, the protocol hopes to draw in professional traders and institutions. Context and potential impact on Curve Finance The proposal comes as Curve continues to modify…
Share
BitcoinEthereumNews2025/09/18 14:37