T
iTokenly

Abracadabra.money (October 2025) hack — October 2025

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedOctober 4, 2025
Target typeLending protocol
Loss$1,790,000Published estimates range $1,700,000 to $1,800,000Price at time of incident
MethodContract logic errorA solvency-check bypass in CauldronV4's cook() batching entry point. Action 5 (borrow) sets a needsSolvencyCheck flag for the end-of-call check; passing the unrecognised action identifier 0 fell through to _additionalCookAction(), which returned a default-initialised CookStatus and overwrote the status struct, clearing the flag. Borrowing and then triggering that path in the same transaction produced an uncollateralised loan the final check never examined. Per Three Sigma, six attacker addresses each borrowed roughly 300,000 MIM to stay under per-address limits; SolidityScan instead describes a single operating address with one self-destructing exploit contract, and reports six deprecated CauldronV4 instances targeted.
ChainsEthereum
OutcomeUsers reimbursed

What happened

Abracadabra.money lets users borrow its dollar-pegged MIM stablecoin against collateral deposited into isolated lending markets called cauldrons. On 4 October 2025, at 12:54:23 UTC, an attacker drained MIM from deprecated CauldronV4 deployments on Ethereum.

The flaw sat in cook(), the entry point that batches several actions into a single transaction. Action 5, the borrow action, sets a flag telling the contract to run a solvency check at the end of the call. Passing the unrecognised action identifier 0 fell through to a path that returned a default-initialised status struct, clearing that flag. Borrowing and then triggering that path in the same call therefore produced an uncollateralised loan that the final check never examined.

Accounts of the scale differ. SolidityScan reports six Cauldron instances targeted, operated from a single attacker address with one exploit contract that later self-destructed. Three Sigma instead describes the borrowing as split across six attacker addresses, each taking roughly 300,000 MIM to stay under per-address limits, against a legacy low-liquidity CauldronV4 deployment dating from February 2023.

Published totals also differ. Three Sigma put the take at about 1,793,755 MIM, worth roughly $1.79 million; SolidityScan counted 1,724,494 MIM, about $1.7 million; Halborn cited approximately $1.8 million. The stolen MIM was routed through DAI, USDC and USDT into roughly 395 ETH and sent to Tornado Cash. None of it has been recovered and no actor has been identified.

Abracadabra paused the affected cauldrons. The DAO later said it had identified and mitigated the vulnerability, confirmed no other cauldrons or user funds were at risk, and bought roughly 1.79 million MIM back from the market, describing the effect of the attack as reversed and no user funds lost. The loss was therefore absorbed by the DAO treasury. It was at least the third exploit of the protocol in under two years, following a January 2024 incident costing about $6.4 million and a March 2025 flash-loan attack costing about $13 million.

Sources

  1. Three SigmaSecondary · retrieved 2026-08-01
  2. SolidityScanSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01
  4. Crypto News AustraliaSecondary · retrieved 2026-08-01
  5. CryptopolitanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Abracadabra.money (October 2025) hack — October 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/abracadabra-money-october-2025
https://itokenly.com/hacks/abracadabra-money-october-2025

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.