An unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affectedAn unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affected

How a governance failure led to the Unleash Protocol hack

2025/12/30 21:40
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
  • An unauthorised contract upgrade enabled direct withdrawals from the protocol.
  • Funds were bridged to Ethereum and laundered through Tornado Cash.
  • Assets affected included WIP, USDC, WETH, stIP, and vIP.

A governance failure at Unleash Protocol has resulted in a major security breach, with attackers draining around $3.9 million in user funds.

The incident was first identified by blockchain security firm PeckShieldAlert and later confirmed by the Unleash team.

While the exploit did not affect the wider Story ecosystem, it has renewed attention on how governance mechanisms can become a critical point of failure in decentralised finance.

Unleash Protocol is a decentralised platform built on Story Protocol.

The project said the incident was limited to its own contracts and administrative controls, with no signs of compromise across Story Protocol’s validators or core infrastructure.

Even so, the event shows how vulnerabilities at the application level can still lead to significant losses.

Governance controls bypassed

On-chain analysis indicates the attacker targeted Unleash Protocol’s multi-signature governance system.

By exploiting weaknesses in how admin permissions were enforced, the attacker gained unauthorised access normally reserved for approved signers.

This access was then used to push through a contract upgrade that had not been sanctioned by the core team.

The unauthorised upgrade altered how the protocol handled withdrawals. With standard governance checks effectively bypassed, the attacker was able to move funds directly out of the protocol.

According to Unleash, these actions occurred outside its established governance framework and were not detected until after the funds had already been removed.

Laundering through bridges and mixers

After extracting the assets, the attacker bridged the funds to Ethereum. From there, the assets were broken into multiple transactions, a strategy often used to make tracking more difficult.

Blockchain data shows that 1,337.1 ETH was later deposited into Tornado Cash. The deposits were made in varying sizes, ranging from small transfers to batches of up to 100 ETH.

This pattern suggests a deliberate attempt to obscure transaction trails and reduce the effectiveness of on-chain monitoring tools.

Tokens impacted

In an official incident notice, Unleash Protocol confirmed that several assets were affected during the exploit.

These included WIP, USDC, WETH, stIP, and vIP.

The team reiterated that all affected withdrawals took place through the unauthorised contract upgrade rather than through normal user interactions.

The clarification that Story Protocol itself was not compromised is significant.

It indicates that the breach stemmed from Unleash’s internal governance design, not from flaws in the underlying blockchain or its validator set.

Emergency measures taken

Following confirmation of the breach, Unleash Protocol paused all platform operations to prevent further losses.

The team said it is working with independent security experts and forensic investigators to determine how the governance safeguards were bypassed and whether additional vulnerabilities remain.

Users have been advised to avoid interacting with Unleash Protocol contracts until further updates are issued.

The project has stated that future communications will be shared only through official channels as the investigation continues.

The post How a governance failure led to the Unleash Protocol hack appeared first on CoinJournal.

시장 기회
유에스디코인 로고
유에스디코인 가격(USDC)
$0.9999
$0.9999$0.9999
0.00%
USD
유에스디코인 (USDC) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!