Bedrock (uniBTC) hack — September 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 27, 2024 |
| Target type | Other |
| Loss | $2,000,000Published estimates range $1,700,000 to $2,000,000Price at time of incident |
| Method | Contract logic errorOne path of uniBTC's minting logic omitted the exchange-rate conversion between ether and bitcoin, so depositing ETH minted the same nominal quantity of uniBTC - a token worth many times more. The vulnerable vault was a permissioned minter for uniBTC, so the mintable quantity was effectively unlimited. The attacker minted uniBTC cheaply and sold it into DEX liquidity pools. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
uniBTC is a synthetic bitcoin token issued by Bedrock, a liquid restaking protocol launched by RockX in February 2023, which held roughly $229 million in total value locked at the time according to Crypto Briefing, though QuillAudits put the figure at over $240 million. On 26 September 2024 the security firm Dedaub found that one path of uniBTC's minting logic did not convert between asset prices: a deposit of ether minted the same nominal quantity of uniBTC, with only decimal scaling applied, so a depositor received a token worth many times what they had put in. The vulnerable vault was a permissioned minter, making the quantity effectively unlimited.
Dedaub confirmed the issue at 16:00 UTC and reported it to Bedrock at 16:27 UTC, with a war room opening at 16:41 UTC. The first exploit transaction landed on Ethereum at 18:28 UTC, before remediation was complete.
Dedaub put the theoretical maximum loss from an infinite-mint scenario at about $75 million, the uniBTC market capitalisation on Ethereum. Most of that was averted when Pendle disabled uniBTC, removing the main exit liquidity, and Bedrock paused the vaults. Pendle alone held over $30 million of uniBTC liquidity on the Corn network.
Loss estimates differ because they measure different things. Dedaub described an initial loss of about $1.8 million, rising to around $2 million taken directly once subsequent swaps were counted. QuillAudits recorded approximately 650 ETH, about $1.7 million, as the primary theft, against a total of about $2 million drained from liquidity pools.
Bedrock published a post-mortem, said remaining reserves were safe, and sent the attacker an on-chain message offering to work together on protocol security; the attacker had not responded as of Cointelegraph's report. Bedrock said a reimbursement plan was being developed. No return of funds has been reported, and completion of the reimbursement could not be confirmed. Bedrock subsequently adopted Chainlink Proof of Reserve to secure the uniBTC minting function.
Sources
- DedaubPrimary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bedrock (uniBTC) hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bedrock-unibtchttps://itokenly.com/hacks/bedrock-unibtcPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.