Tools Crypto Exploit Tracker exploit-0078
Exploit record
Unleash Protocol
- Loss
- $4M
- Attack vector
- Access Control
- Chain
- Story
- Sector
- Governance
What happened
On December 30, 2025, Unleash Protocol's multisig governance was compromised, enabling an unauthorised upgrade and a drain of roughly $3.9M.
This was a permissions story. Once the attacker acquired governance-side control, the rest followed in depressingly familiar fashion: upgrade logic, withdraw assets, bridge out, launder through Tornado. Story itself said its core infrastructure was unaffected, which may be true, but that is cold comfort when the application sitting on top of it has been opened with admin keys.
On-chain references
- Attacker Address
0xc946981F5dFBFA10cf858B95d51Fc06DCD15BfE3 - Story txstoryscan.io/tx/0x2cb543fdcb7345fd4b6512b9b37408fbaeded6a06b…
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
