The attack allowed malicious actors to drain 6,260 ETH by exploiting vulnerabilities within Abracadabra’s smart contract infrastructure.
This event marks the second significant breach for the platform this year, following a $6.49 million exploit in January that temporarily debugged MIM.
In the wake of the attack, Abracadabra took swift action to mitigate the impact. The project’s DAO treasury, which holds around $19 million in assets, repurchased 6.5 million MIM to cover 50% of the loss.
Abracadabra: The gmCauldrons product was hacked yesterday, resulting in a loss of approximately 13 million MIM (~6,000 ETH). The DAO treasury has urgently utilized a portion of its assets to repurchase 6.5 million MIM, accounting for 50% of the total loss, with the remaining… https://t.co/CBlBnUjfJr
The project is now focusing on post-mortem analysis, improved security measures, and long-term remediation plans to rebuild trust within its community.
Security Oversight and Treasury Remediation Plan
Despite multiple layers of security, including audits by Guardian Audits and real-time monitoring by firms like Hexagate and ZeroShadow, the attacker managed to bypass defenses.
According to the report released, while ZeroShadow quickly traced the attack, Hexagate failed to trigger an alert during the exploit.
The report highlighted unforeseen vulnerabilities in gmCauldrons, a critical component of the Abracadabra ecosystem that allows users to collateralize GMX-based tokens to borrow MIM.
Security Update:
The hackers’s funds have been consolidated over 3 wallets:
To address the situation, Abracadabra has initiated a phased remediation strategy.
The DAO treasury’s holdings, currently valued at $19 million, include a $4 million Depeg Contingency Fund that can be deployed following a governance proposal.
In the immediate aftermath, the treasury allocated funds to buy back and burn 6.5 million MIM, effectively neutralizing half of the exploited debt. By mid-2025, the remaining losses will be systematically covered through treasury funds.
Abracadabra emphasized that the MIM peg remained stable throughout the crisis, with only minor deviations from its $1 value.
Moving forward, the project aims to strengthen its treasury by diversifying holdings and implementing stricter risk controls to ensure resilience against future attacks.
Expanding Ecosystem and Future Developments
While addressing the immediate crisis, Abracadabra is also looking toward future expansion. The DAO has outlined four key initiatives to strengthen its platform.
$13M exploit.
50% repaid in less than 36h. Zero user funds lost.
First is the Berachain Expansion, which is a new set of cauldrons set to launch on Berachain. These cauldrons will allow users to collateralize various liquidity pool (LP) tokens to mint MIM.
These include WBERA-WETH, WBERA-WBTC, and MIM-USDT0 vaults. Additionally, Omnichain SPELL, built on the OFT v2 standard, will soon be deployed to improve liquidity across multiple networks.
Second is the Nibiru Integration. This particular one follows the approval of AIP 62, with MIMswap now preparing to launch on Nibiru, providing a stable swap solution for the ecosystem.
Further governance proposals will determine the deployment of additional MIM cauldrons.
The third is the Purrswap Incubation, which is the first AbracadabraDAO incubation project.
Purrswap will introduce a stable swap on HyperEVM. The integration will feature a SPELL holder airdrop, reinforcing DAO participation and liquidity provision.
Lastly, in response to the attack, Abracadabra is collaborating with Chainalysis to track stolen funds and working closely with centralized exchanges to prevent further illicit transactions.
Security Update:
The hackers’s funds have been consolidated over 3 wallets:
The project has also extended an offer to the hacker for negotiations in exchange for a bug bounty.
As it stands now, Abracadabra is actively engaging with on-chain security experts to track stolen funds and prevent laundering through centralized exchanges.
The DAO has made it clear that it is willing to negotiate a return of stolen funds in exchange for a bounty reward.
The team has encouraged anyone with information to contact them via on-chain messages or email.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.