Abracadabra Suffers Third DeFi Exploit As Hackers Drain $1.7 million
Abracadabra has suffered its third major breach in two years, reigniting scrutiny over the project’s code security and DeFi risk controls.
DeFi project Abracadabra has suffered a fresh exploit that drained about $1.7 million from its platform.
Blockchain security firm Go Security flagged the breach on October 4 and confirmed that attackers had already laundered about 51 ETH through Tornado Cash. At the time of reporting, the attacker’s wallet (identified as 0x1AaaDe) still held around 344 ETH, worth approximately $1.55 million.
How Abracadabra Was Exploited for the Third Time
Security researcher Weilin Li verified the exploit and explained that the attacker manipulated Abracadabra’s smart contract variables to bypass a solvency check.
This allowed them to borrow assets beyond the intended limit, prompting Abracadabra’s team to pause all contracts to prevent further losses.
Another blockchain audit firm, Phalcon, traced the root cause to a faulty logic sequence in the platform’s cook function. This is a mechanism that lets users execute several predefined actions in one transaction.
.@MIM_Spell was attacked hours ago, resulting in a loss of ~$1.7M. The root cause stems from the flawed implementation logic of the cook function, which allows users to execute multiple predefined operations in a single transaction. Specifically, the actions share a common… pic.twitter.com/4tQzkRbwcT
— BlockSec Phalcon (@Phalcon_xyz) October 4, 2025
According to the firm, the attacker carried out two operations that overrode key safeguards.
The first, known as action 5, initiated a borrowing process that was supposed to pass solvency checks. The second, called action 0, acted as an empty update function that rewrote the check flag and skipped the final validation step.
The attacker drained more than 1.79 million MIM tokens by repeating this pattern across six different addresses.
As of press time, Abracadabra has yet to comment publicly on the incident. Notably, the project’s official X account has remained silent since early September.
However, Go Security reported that the Abracadabra team confirmed on Discord that it would use DAO reserve funds to repurchase the affected MIM supply.
🚨 GoPlus Security Alert: The lending and stablecoin platform Abracadabra ( $SPELL ) appears to have been attacked again, with losses of approximately $1.77 million. Its official Twitter account @MIM_Spell has not been updated since September 9.Attacker Address:… pic.twitter.com/IjECKsOCWX
— GoPlus Security 🚦 (@GoPlusSecurity) October 5, 2025
Meanwhile, if verified, the latest incident would mark the third exploit against Abracadabra in under two years.
In January 2024, the platform lost $6.49 million in a hack that briefly depegged the MIM stablecoin from the US dollar. A second exploit in March 2025 drained another $13 million from its cauldron contracts, after which the team offered the hacker a 20% bounty.
The recurrence of such breaches raises renewed questions about the security of the DeFi protocol and the sustainability of its cross-chain lending architectures.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Bolivia eyes crypto and stablecoins to fight inflation and US dollar shortage

COTI and Houdini Swap Integrate Privacy and Regulatory Compliance to Support Institutional Blockchain Integration
- COTI partners with Houdini Swap to enable confidential cross-chain swaps, preserving user privacy while maintaining regulatory compliance for institutional adoption. - The integration uses non-custodial architecture and split-transaction routing to obscure sender-receiver links while allowing KYT checks on regulated exchanges. - COTI's Garbled Circuits infrastructure supports enterprise-grade privacy, enabling full lifecycle compliance from asset swaps to DeFi interactions without data exposure. - With $

XRP News Update: XRP ETF Momentum and Institutional Interest Face Off Against Technical Challenges in $15.5 Trillion Pursuit
- XRP gains traction via spot ETF approvals and institutional adoption, unlocking a $15.5T market potential as Ripple expands into prime brokerage and cross-border payments. - SEC-approved ETFs from Bitwise, 21Shares, and Grayscale attract $645M in AUM, offering investors regulated access to XRP with fees ranging from 0.34% to 1.89%. - Ripple's $1.25B acquisition of Hidden Road (Ripple Prime) enhances XRP's utility as collateral for $3T in annual settlements, boosting institutional liquidity and adoption.
Bitcoin Leverage Liquidations: Potential Impact on Institutional Involvement in 2025
- 2025 crypto market saw $19B in Bitcoin liquidations after October 10 crash, slashing prices from $126k to $82k amid 70% long-position collapses. - 1,001:1 leverage ratios and 78% perpetual futures dominance created self-reinforcing sell-offs, exposing systemic risks in hyper-leveraged derivatives. - Fed rate hikes and the GENIUS Act's stablecoin rules intensified volatility, forcing institutions to adopt AIFM risk models and RWA diversification. - Post-crisis reforms show $73.59B in crypto-collateralized

