Abracadabra Suffers Third DeFi Exploit As Hackers Drain $1.7 million
Abracadabra has suffered its third major breach in two years, reigniting scrutiny over the project’s code security and DeFi risk controls.
DeFi project Abracadabra has suffered a fresh exploit that drained about $1.7 million from its platform.
Blockchain security firm Go Security flagged the breach on October 4 and confirmed that attackers had already laundered about 51 ETH through Tornado Cash. At the time of reporting, the attacker’s wallet (identified as 0x1AaaDe) still held around 344 ETH, worth approximately $1.55 million.
How Abracadabra Was Exploited for the Third Time
Security researcher Weilin Li verified the exploit and explained that the attacker manipulated Abracadabra’s smart contract variables to bypass a solvency check.
This allowed them to borrow assets beyond the intended limit, prompting Abracadabra’s team to pause all contracts to prevent further losses.
Another blockchain audit firm, Phalcon, traced the root cause to a faulty logic sequence in the platform’s cook function. This is a mechanism that lets users execute several predefined actions in one transaction.
.@MIM_Spell was attacked hours ago, resulting in a loss of ~$1.7M. The root cause stems from the flawed implementation logic of the cook function, which allows users to execute multiple predefined operations in a single transaction. Specifically, the actions share a common… pic.twitter.com/4tQzkRbwcT
— BlockSec Phalcon (@Phalcon_xyz) October 4, 2025
According to the firm, the attacker carried out two operations that overrode key safeguards.
The first, known as action 5, initiated a borrowing process that was supposed to pass solvency checks. The second, called action 0, acted as an empty update function that rewrote the check flag and skipped the final validation step.
The attacker drained more than 1.79 million MIM tokens by repeating this pattern across six different addresses.
As of press time, Abracadabra has yet to comment publicly on the incident. Notably, the project’s official X account has remained silent since early September.
However, Go Security reported that the Abracadabra team confirmed on Discord that it would use DAO reserve funds to repurchase the affected MIM supply.
🚨 GoPlus Security Alert: The lending and stablecoin platform Abracadabra ( $SPELL ) appears to have been attacked again, with losses of approximately $1.77 million. Its official Twitter account @MIM_Spell has not been updated since September 9.Attacker Address:… pic.twitter.com/IjECKsOCWX
— GoPlus Security 🚦 (@GoPlusSecurity) October 5, 2025
Meanwhile, if verified, the latest incident would mark the third exploit against Abracadabra in under two years.
In January 2024, the platform lost $6.49 million in a hack that briefly depegged the MIM stablecoin from the US dollar. A second exploit in March 2025 drained another $13 million from its cauldron contracts, after which the team offered the hacker a 20% bounty.
The recurrence of such breaches raises renewed questions about the security of the DeFi protocol and the sustainability of its cross-chain lending architectures.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Crypto Drives Change: IPSI’s Insurance Arm Adopts Instant Blockchain-Based Payments
- Innovative Payment Solutions (OTC: IPSI) formed Astria Insurance Solutions, a subsidiary integrating crypto-based premium payments with fintech and insurance services. - Astria uses IPSI's blockchain infrastructure for real-time settlements and digital wallets, aligning with crypto adoption trends in finance . - The subsidiary plans to secure state licenses and expand via a marketing platform, targeting digital-first consumers and commercial clients. - CEO Bill Corbett emphasized the strategic value of m

Bitcoin News Today: Bitcoin Faces Volatility Turning Point as Whale's 20x Leverage Bet Challenges $88,900 Mark
- A dormant Bitcoin whale reactivated after 18 months, opening a $31M 20x leveraged long position, signaling bullish confidence in Bitcoin's $88,900 threshold. - The position faces liquidation risks if Bitcoin dips below $88,900, amid $563M in cumulative long liquidation risks and $745M short risks across major exchanges. - Other large holders show divergent strategies: a 14-year-old miner moved $16.6M BTC amid quantum computing concerns, while a 20x short seller holds $24M in unrealized profits. - Analyst

XRP News Today: XRP Declines as ETF Investments Unable to Halt Downward Momentum
- XRP fell below $2.00 as macroeconomic uncertainty and ETF inflows failed to reverse its bearish trend despite $105M in Bitwise ETF inflows. - Futures Open Interest dropped to $3.57B, whale sales of 200M XRP, and institutional outflows accelerated the decline below key technical levels. - Technical indicators show RSI at 43 and negative MACD, with analysts warning of potential 50% declines to $1.25 if $2.00 support breaks. - The SEC-approved Bitwise 10 Crypto Index ETF (4.97% XRP allocation) may reshape d

Data Shortfalls and Policy Conflicts Prevent Fed from Lowering Rates in December
- The Fed’s December rate cut prospects have dimmed, with officials citing data gaps and inflation concerns, reducing the CME FedWatch probability to 32%. - Delayed BLS labor market reports left policymakers without critical metrics, fueling skepticism about justifying a cut amid internal divisions. - Officials like Christopher Waller argue for easing due to a "stall speed" labor market, while Lorie Logan and Beth Hammack caution against premature cuts risking inflation and market instability. - Markets ha

