An unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affectedAn unauthorised contract upgrade enabled direct withdrawals from the protocol. Funds were bridged to Ethereum and laundered through Tornado Cash. Assets affected

How a governance failure led to the Unleash Protocol hack

  • An unauthorised contract upgrade enabled direct withdrawals from the protocol.
  • Funds were bridged to Ethereum and laundered through Tornado Cash.
  • Assets affected included WIP, USDC, WETH, stIP, and vIP.

A governance failure at Unleash Protocol has resulted in a major security breach, with attackers draining around $3.9 million in user funds.

The incident was first identified by blockchain security firm PeckShieldAlert and later confirmed by the Unleash team.

While the exploit did not affect the wider Story ecosystem, it has renewed attention on how governance mechanisms can become a critical point of failure in decentralised finance.

Unleash Protocol is a decentralised platform built on Story Protocol.

The project said the incident was limited to its own contracts and administrative controls, with no signs of compromise across Story Protocol’s validators or core infrastructure.

Even so, the event shows how vulnerabilities at the application level can still lead to significant losses.

Governance controls bypassed

On-chain analysis indicates the attacker targeted Unleash Protocol’s multi-signature governance system.

By exploiting weaknesses in how admin permissions were enforced, the attacker gained unauthorised access normally reserved for approved signers.

This access was then used to push through a contract upgrade that had not been sanctioned by the core team.

The unauthorised upgrade altered how the protocol handled withdrawals. With standard governance checks effectively bypassed, the attacker was able to move funds directly out of the protocol.

According to Unleash, these actions occurred outside its established governance framework and were not detected until after the funds had already been removed.

Laundering through bridges and mixers

After extracting the assets, the attacker bridged the funds to Ethereum. From there, the assets were broken into multiple transactions, a strategy often used to make tracking more difficult.

Blockchain data shows that 1,337.1 ETH was later deposited into Tornado Cash. The deposits were made in varying sizes, ranging from small transfers to batches of up to 100 ETH.

This pattern suggests a deliberate attempt to obscure transaction trails and reduce the effectiveness of on-chain monitoring tools.

Tokens impacted

In an official incident notice, Unleash Protocol confirmed that several assets were affected during the exploit.

These included WIP, USDC, WETH, stIP, and vIP.

The team reiterated that all affected withdrawals took place through the unauthorised contract upgrade rather than through normal user interactions.

The clarification that Story Protocol itself was not compromised is significant.

It indicates that the breach stemmed from Unleash’s internal governance design, not from flaws in the underlying blockchain or its validator set.

Emergency measures taken

Following confirmation of the breach, Unleash Protocol paused all platform operations to prevent further losses.

The team said it is working with independent security experts and forensic investigators to determine how the governance safeguards were bypassed and whether additional vulnerabilities remain.

Users have been advised to avoid interacting with Unleash Protocol contracts until further updates are issued.

The project has stated that future communications will be shared only through official channels as the investigation continues.

The post How a governance failure led to the Unleash Protocol hack appeared first on CoinJournal.

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.0012
$1.0012$1.0012
+0.02%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shiba Inu Supply Shrinks as 167,991,300,000 SHIB Exit Exchanges

Shiba Inu Supply Shrinks as 167,991,300,000 SHIB Exit Exchanges

The post Shiba Inu Supply Shrinks as 167,991,300,000 SHIB Exit Exchanges appeared on BitcoinEthereumNews.com. -167,991,300,000 SHIB in exchange netflow Shiba Inu
Share
BitcoinEthereumNews2026/01/01 04:42
Kan de Solana koers naar $129 door grote SOL ETF instroom en hoge netwerkinkomsten?

Kan de Solana koers naar $129 door grote SOL ETF instroom en hoge netwerkinkomsten?

Solana sluit 2025 af met meer dan $1,5 miljard aan netwerkinkomsten. Daarmee laat het netwerk Ethereum en Hyperliquid samen achter zich. Deze cijfers van Blockworks
Share
Coinstats2026/01/01 03:16
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41