## Unleash Protocol Exploit: how $3.9 million was drained due to a governance vulnerability
Security researchers from PeckShield have identified a serious incident on the decentralized platform Unleash Protocol, which operates on the Story Protocol. The attacker exploited a vulnerability in the multi-signature management system and successfully withdrew approximately $3.9 million of user assets. The incident highlights the critical importance of safeguarding administrative control in the DeFi ecosystem.
## Anatomy of the breach: from unauthorized access to fund withdrawal
The attack began with the compromise of the Unleash Protocol's multi-signature mechanism. The attacker gained unauthorized administrative access and implemented an unauthorized smart contract update that bypassed standard approval procedures. This gave the attacker direct control over the protocol and the ability to withdraw funds from the contracts without internal team approval.
After draining assets from the protocol, the attacker started splitting the stolen funds into small parts to complicate tracking. On the Ethereum blockchain, deposits totaling 1,337.1 ETH were recorded, which were sent to Tornado Cash — a popular privacy tool used to obscure the origin of transactions. The system of multiple deposits (from small amounts to batches of 100 ETH) was clearly aimed at mixing assets through a mixer protocol to eliminate links between the stolen funds and the original source.
## Which assets were affected
During the exploit, several key tokens in the ecosystem were compromised: WIP, USDC, WETH, stIP, and vIP. All these assets were withdrawn outside of the approved governance without the consensus of the core team. The Unleash Protocol team emphasized that the incident is limited solely to the protocol's contracts — its validator nodes and underlying infrastructure remain untouched.
## Platform actions and user recommendations
Shortly after discovering the vulnerability, Unleash Protocol suspended all operations to prevent further losses. The team initiated an investigation together with independent security experts and forensic specialists. Currently, users are strongly advised to refrain from interacting with Unleash Protocol contracts until official updates regarding the vulnerability fix are released.
This incident once again demonstrates the importance of regular security audits, multi-factor confirmation for critical governance operations, and adequate monitoring of administrative access in DeFi protocols.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
## Unleash Protocol Exploit: how $3.9 million was drained due to a governance vulnerability
Security researchers from PeckShield have identified a serious incident on the decentralized platform Unleash Protocol, which operates on the Story Protocol. The attacker exploited a vulnerability in the multi-signature management system and successfully withdrew approximately $3.9 million of user assets. The incident highlights the critical importance of safeguarding administrative control in the DeFi ecosystem.
## Anatomy of the breach: from unauthorized access to fund withdrawal
The attack began with the compromise of the Unleash Protocol's multi-signature mechanism. The attacker gained unauthorized administrative access and implemented an unauthorized smart contract update that bypassed standard approval procedures. This gave the attacker direct control over the protocol and the ability to withdraw funds from the contracts without internal team approval.
After draining assets from the protocol, the attacker started splitting the stolen funds into small parts to complicate tracking. On the Ethereum blockchain, deposits totaling 1,337.1 ETH were recorded, which were sent to Tornado Cash — a popular privacy tool used to obscure the origin of transactions. The system of multiple deposits (from small amounts to batches of 100 ETH) was clearly aimed at mixing assets through a mixer protocol to eliminate links between the stolen funds and the original source.
## Which assets were affected
During the exploit, several key tokens in the ecosystem were compromised: WIP, USDC, WETH, stIP, and vIP. All these assets were withdrawn outside of the approved governance without the consensus of the core team. The Unleash Protocol team emphasized that the incident is limited solely to the protocol's contracts — its validator nodes and underlying infrastructure remain untouched.
## Platform actions and user recommendations
Shortly after discovering the vulnerability, Unleash Protocol suspended all operations to prevent further losses. The team initiated an investigation together with independent security experts and forensic specialists. Currently, users are strongly advised to refrain from interacting with Unleash Protocol contracts until official updates regarding the vulnerability fix are released.
This incident once again demonstrates the importance of regular security audits, multi-factor confirmation for critical governance operations, and adequate monitoring of administrative access in DeFi protocols.