cryptonews
2025-06-25 13:27:26

Ex-Employee Hacks Bedrock UniBTC for $2M: Fuzzland Uncovers Insider Exploit

Fuzzland has disclosed a $2 million insider attack that targeted Bedrock’s UniBTC protocol in September 2024, was carried out by a former employee who used malware, social engineering, and privileged access to compromise internal systems. Fuzzland has taken full responsibility for the breach and reimbursed all affected parties. Insider Access Used in $2M Bedrock Protocol Exploit Fuzzland, in a post on X, revealed that a past employee exploited the UniBTC protocol via a sophisticated insider operation. The individual joined the company under the guise of a skilled MEV developer and later inserted a trojan into Fuzzland’s MEV codebase using a malicious Rust crate named rands. https://t.co/zGdP4bKWzI — 𝕗𝕦𝕫𝕫𝕝𝕒𝕟𝕕 (@fuzzland_) June 23, 2025 The attack vector began with social engineering. The former employee impressed during interviews and demonstrated a functioning MEV bot, earning access to the company’s infrastructure. On September 4, 2024, the attacker modified the project’s Cargo.toml file to include the trojan, which auto-executed in commonly used IDEs such as VSCode and JetBrains. The malware allowed persistent, undetected access to engineering workstations for over three weeks. Security tools such as Falcon and AVG failed to detect the intrusion. However, on September 26, Fuzzland discussed a vulnerability in UniBTC, discovered in a Dedaub report, during an emergency call. Just over an hour later, at 18:28 UTC, the UniBTC protocol was exploited. @Bedrock_DeFi , a multi-asset liquid staking protocol, has confirmed it suffered a security breach involving its synthetic Bitcoin token, uniBTC. #Hack #DeFi https://t.co/fRStCw7hK1 — Cryptonews.com (@cryptonews) September 27, 2024 In response, Fuzzland compensated Bedrock for its losses using company funds. The firm enlisted Web3 security firm zeroShadow to investigate the breach and rule out any internal collusion. It also filed reports with both the FBI and Chinese law enforcement to pursue criminal action. Despite the attack, Bedrock’s total value locked (TVL) grew from $240 million in September 2024 to $535 million in June 2025, according to DeFiLlama data. Fuzzland Launches Major Security Revamp Amid Industry-Wide Spike in Crypto Hacks To safeguard its systems from future incidence, Fuzzland launched new internal controls and adopted enhanced vetting procedures. This includes on-site employee screenings, detailed know-your-employee (KYE) verification, and strict privilege separation. Sensitive systems remain isolated, and private keys are secured in trusted execution environments (TEEs). According to its report, Fuzzland has implemented software bill of materials (SBOM) checks across all codebases. This ensures that any malicious dependencies are flagged before deployment. Fuzzland also expanded its source code analysis capabilities by integrating tools like CodeQL and CodeRabbit. Additionally, Fuzzland reinforced its protocols for handling intelligence under TLP:RED, ensuring strict need-to-know access for vulnerability information. Fuzzland also acknowledged the contributions of Bedrock, SEAL 911 , Slowmist, and zeroShadow in coordinating a swift response. It shared threat indicators such as suspicious IP addresses and malware samples on VirusTotal to assist the broader security community. Crypto hacks and scams hit $364M in April, driven by a $331M phishing heist as social engineering threats surge. #CryptoHacks #BlockchainSecurity https://t.co/4xOe5Qnpkr — Cryptonews.com (@cryptonews) May 1, 2025 Notably, the crypto industry continues to see a rise in crypto hacks driven by phishing and social engineering. Blockchain security firm CertiK reported that over $364 million was stolen in April 2025. This amounted to a 1,163% surge from the $28.8 million stolen in March. In one of the year’s most severe breaches, hackers stole 3,520 Bitcoins worth $330.7 million from a U.S. senior citizen. Meanwhile, the biggest hack to date remains the Bybit hack on February 21. The exchange suffered a major security breach, resulting in hack of a $1.5 billion worth of ETH . The post Ex-Employee Hacks Bedrock UniBTC for $2M: Fuzzland Uncovers Insider Exploit appeared first on Cryptonews .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.