Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 17, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 17, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 17, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 17, 2025

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025

      If you think you can do better than Xbox or PlayStation in the Console Wars, you may just want to try out this card game

      May 17, 2025

      Surviving a 10 year stint in dev hell, this retro-styled hack n’ slash has finally arrived on Xbox

      May 17, 2025

      Save $400 on the best Samsung TVs, laptops, tablets, and more when you sign up for Verizon 5G Home or Home Internet

      May 17, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      NodeSource N|Solid Runtime Release – May 2025: Performance, Stability & the Final Update for v18

      May 17, 2025
      Recent

      NodeSource N|Solid Runtime Release – May 2025: Performance, Stability & the Final Update for v18

      May 17, 2025

      Big Changes at Meteor Software: Our Next Chapter

      May 17, 2025

      Apps in Generative AI – Transforming the Digital Experience

      May 17, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025
      Recent

      Microsoft’s allegiance isn’t to OpenAI’s pricey models — Satya Nadella’s focus is selling any AI customers want for maximum profits

      May 17, 2025

      If you think you can do better than Xbox or PlayStation in the Console Wars, you may just want to try out this card game

      May 17, 2025

      Surviving a 10 year stint in dev hell, this retro-styled hack n’ slash has finally arrived on Xbox

      May 17, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Abracadabra Cyberattack: How Hackers Drained $13M from DeFi Platform

    Abracadabra Cyberattack: How Hackers Drained $13M from DeFi Platform

    March 26, 2025

    Abracadabra Cyberattack

    The decentralized finance (DeFi), Abracadabra, is dealing with a cyberattack that resulted in the theft of nearly $13 million worth of cryptocurrency. The Abracadabra cyberattack, which targeted the platform’s “gmCauldrons,” has shaken the cryptocurrency market particularly those that rely on liquidity tokens from decentralized exchanges like GMX.

    Decoding the Abracadabra Cyberattack 

    The cyberattack on Abracadabra occurred in March 2025 and drained 6,260 ETH, valued at approximately $12.98 million at the time. The exploit was flagged by blockchain security firm PeckShield, which identified suspicious transactions involving contracts from Abracadabra and decentralized exchange GMX. These contracts were connected to gmCauldrons, isolated lending markets within Abracadabra that allowed users to borrow against crypto collateral. 

    Decoding the Abracadabra Cyberattack 
    Details of the Abracadabra attack (Soure: X)

    The gmCauldrons in question were designed to use GM tokens—liquidity positions from GMX—however, it was these specific cauldrons, not the GMX platform itself, that were compromised. GMX, which operates as a decentralized exchange, distanced itself from the incident.

    GMX Communications
    Tweet from GMX Communications’ Contributor (Source: X)

    According to GMX Communications Contributor Jonezee, “To clarify, GMX contracts are not affected. The exploit relates solely to Abracadabra’s gmCauldrons based on GMX V2’s GM pools. We’re deeply sorry for anyone affected by this unfortunate situation.” 

    Abracadabra’s Response to the Attack 

    Following the breach, Abracadabra quickly issued a statement acknowledging the exploit, assuring its users that no collateral was affected, and only the gmCauldrons had been targeted. The platform explained that its gmCauldrons had undergone rigorous auditing by Guardian Audits, the same firm responsible for auditing GMX’s core contracts. Despite these security measures, the cyberattack on Abracadabra wasn’t detected until the hacker had already executed several transactions. 

    Abracadabra’s team moved quickly to mitigate the damage. With the help of Zeroshadow, a security firm, the team turned off all borrows to the affected cauldrons to prevent further exploitation. They also confirmed that funds from the attack were consolidated across three addresses, and they were in close contact with Chainalysis, a blockchain forensics firm, to trace the stolen funds. 

    To resolve the situation, Abracadabra has even offered the hacker a 20% bug bounty, with an invitation to negotiate the return of the funds. A message was sent via on-chain communication, and the protocol shared an email address for the hacker to contact them if they wished to discuss the matter further. Abracadabra also stated that a full post-mortem report would be provided once the investigation is concluded.

    A Broader Look at the Abracadabra Data Breach and the Impact on GMX 

    Abracadabra Data Breach and the Impact on GMX 
    Statement from Jonezee in GMX (Source: Telegram)

    While the exploit was primarily confined to Abracadabra’s gmCauldrons, it has stirred up concerns within the broader DeFi community. GMX, which was not directly impacted by the breach, clarified that the attack was restricted to Abracadabra’s infrastructure. GMX reiterated that its contracts were secure and unaffected by the cyberattack on Abracadabra. GMX, a popular decentralized exchange, offers users the ability to trade assets like BTC, ETH, and SOL with up to 100x leverage, directly from their wallets.

    Jonezee of GMX explained, “We believe the issue relates solely to the Abracadabra/Spell cauldrons. These cauldrons allow for borrowing against specific GM liquidity tokens, but the GMX platform itself has not been compromised.” 

    Security experts have been working together to investigate the cause of the exploit, including teams from Guardian Audits, GMX, and other security researchers. The full details of how the exploit was carried out remain under investigation. 

    Tracking the Stolen Funds 

    Abracadabra data breach
    Security Update on Hackers’ Wallet (Source: X)

    As of the latest update, the stolen funds from the Abracadabra data breach have been consolidated across three wallets, with the addresses being tracked by Chainalysis and Zeroshadow’s monitoring team. The stolen cryptocurrency, which includes 6,260 ETH, was bridged to the Ethereum network and distributed across multiple addresses, making it more difficult to trace the movement of the funds. The addresses identified in the attack include: 

    • 0x018182FD7B856AeE1606D7E0AA8bca10F1Cb0b5d 
    • 0xa8f822E937C982e65b0437Ac81792a3AdA76A1ff 
    • 0x047C2a3dd1Ab4105B365685d4804fE5c440B5729 

    Despite the complex nature of the hack, Abracadabra’s security infrastructure, including partnerships with Zeroshadow and Chainalysis, has played a crucial role in tracking the movement of the stolen funds. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAI-Powered Productivity or Security Nightmare? The Risks of Enterprise AI
    Next Article Malaysia Braces for Cyberattacks During Hari Raya: Cyber999 Issues Warning

    Related Posts

    Development

    February 2025 Baseline monthly digest

    May 17, 2025
    Development

    Learn A1 Level Spanish

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Setting Up a Secure Mail Server with Dovecot on Ubuntu Server

    Learning Resources

    Unlocking the Secrets of Smart Automation

    Web Development

    Researchers from KAUST and Harvard Introduce MiniGPT4-Video: A Multimodal Large Language Model (LLM) Designed Specifically for Video Understanding

    Development

    CVE-2025-3224 – Docker Desktop for Windows Elevation of Privilege Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    Development

    Meet Andesite AI: An Advanced AI Security Analytics Startup that Empowers both Private- and Public-Sector Cyber Experts

    April 15, 2024

    Artificial intelligence (AI) has the potential to transform cyber defense. One of the biggest challenges…

    Cracking the Code of AI Alignment: This AI Paper from the University of Washington and Meta FAIR Unveils Better Alignment with Instruction Back-and-Forth Translation

    August 17, 2024

    SEIKO EPSON Printer Vulnerabilities Let Attackers Execute Arbitrary Code

    April 28, 2025

    CVE-2025-21470 – Apache Image Toolkit Buffer Overflow

    May 6, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.