Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Abracadabra offers hacker 20% bounty after $13M breach

Abracadabra offers hacker 20% bounty after $13M breach

Crypto.News2025/03/24 16:00
By: By Micah ZimmermanEdited by Jayson Derrick
ARB+0.57%GMX+1.11%ETH+0.11%

Abracadabra Finance has confirmed a security exploit affecting its gmCauldron smart contracts, resulting in the theft of approximately $13 million and is taking steps to recover the funds.

The protocol has since disabled borrowing across all cauldrons and is working with blockchain security firms to track the stolen funds, according to a company statement.

The attack , which blockchain security firm PeckShield first flagged , targeted the integration between GMX decentralized exchange and Abracadabra’s lending contracts. 

“The full damage of the attack is currently being assessed. We are working together with Guardian Audits, GMX, and other security peers to identify the execution of the hack,” the company posted .

Abracadabra noted that its gmCauldrons underwent audits by Guardian Audits before deployment and were integrated into multiple security monitoring systems — including Zeroshadow tracking and Hexagate response software. Despite these measures, the breach was only detected after the attacker executed multiple transactions.

The Zeroshadow team eventually alerted Abracadabra, prompting an immediate shutdown of all borrowing functions.

. @GMX_IO @MIM_Spell related contracts have been hacked for ~6,260 ETH (worth ~$13M) pic.twitter.com/LZzMADWB3n

— PeckShield Inc. (@peckshield) March 25, 2025

Blockchain analytics firm Chainalysis has been enlisted to track the stolen assets, which have been bridged from Arbitrum ( ARB ) to Ethereum ( ETH ) and consolidated into at least three addresses.

Abracadabra is offering the attacker a 20% bug bounty to return the remaining funds, stating:

“To the hacker, we are happy to entertain negotiations for a bug bounty of 20% of the total. Reach out at [email protected] or on-chain to our treasury address on ETH 0xDF2C270f610Dc35d8fFDA5B453E74db5471E126B.”

A full post-mortem of the latest exploit will be released once the investigation is complete, the company said.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — BARD/USDT!
Bitget Announcement2025/09/19 07:28
BTC/ETH VIP Earn Ultimate Carnival is officially here!
Bitget Announcement2025/09/18 07:12
New spot margin trading pair — FLOCK/USDT!
Bitget Announcement2025/09/18 06:55
0GUSDT now launched for pre-market futures trading
Bitget Announcement2025/09/18 05:39

Trending news

More
1
New spot margin trading pair — BARD/USDT!
2
BTC/ETH VIP Earn Ultimate Carnival is officially here!

Crypto prices

More
Bitcoin
Bitcoin
BTC
$115,749.54
-1.42%
Ethereum
Ethereum
ETH
$4,476.3
-2.84%
XRP
XRP
XRP
$3
-2.69%
Tether USDt
Tether USDt
USDT
$1
+0.03%
BNB
BNB
BNB
$986.87
+0.18%
Solana
Solana
SOL
$239.68
-3.35%
USDC
USDC
USDC
$0.9999
+0.03%
Dogecoin
Dogecoin
DOGE
$0.2672
-5.04%
TRON
TRON
TRX
$0.3440
-2.05%
Cardano
Cardano
ADA
$0.8966
-3.81%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter