Seedify hack — September 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 23, 2025 |
| Target type | Cross-chain bridge |
| Loss | $1,200,000Published estimates range $1,200,000 to $1,700,000Price at time of incident |
| Method | Private key compromiseA compromised developer key held owner rights over Seedify's LayerZero OFT bridge contract on Avalanche. The attacker changed the contract's configuration, minted roughly 8.79 million unbacked SFUND, bridged them to other networks and sold them into liquidity pools. |
| Chains | Avalanche, BNB Chain, Ethereum, Arbitrum, Base |
| Audited beforehand | Yes |
| Attributed to | DPRK-linked "Contagious Interview" clusterSuspected |
| Outcome | Unresolved |
What happened
At about 12:05 UTC on 23 September 2025 an attacker minted unbacked SFUND tokens through Seedify's cross-chain bridge and sold them into liquidity pools on several networks. Seedify, a blockchain gaming launchpad, said the attacker had obtained a developer's private key that carried owner rights over its LayerZero OFT bridge contract on Avalanche. The entry point was the key rather than a code defect; the team said the bridge contracts had previously passed audits.
With owner access the attacker altered the contract's configuration and minted roughly 8.79 million SFUND, then bridged the tokens to Ethereum, Arbitrum, Base and BNB Chain and sold them. SFUND's price collapsed by close to 99 percent before partially recovering.
The loss has been reported at two levels. Contemporaneous reporting by crypto.news and others put the value taken from liquidity at more than $1.2 million and counted about 64,000 affected SFUND holders on BNB Chain. Other outlets cite roughly $1.7 million across all chains without identifying who produced that estimate or how it was reached. Neither figure has been reconciled and Seedify did not publish an itemised accounting.
Seedify disabled its bridges, blacklisted the attacker's addresses and asked exchanges to halt trading. Changpeng Zhao said security contacts helped freeze about $200,000 at HTX; the remainder stayed on-chain. The on-chain investigator ZachXBT tied the addresses to the North Korean "Contagious Interview" cluster, and Seedify's founder publicly blamed DPRK-affiliated attackers. That attribution rests on researcher analysis and the company's own claim, not on charges or a government finding.
Law enforcement
Seedify said it was working with partners and authorities; no charges or formal government attribution have been announced.
Sources
- crypto.newsSecondary · retrieved 2026-08-01
- Brave New CoinSecondary · retrieved 2026-08-01
- OurCryptoTalkSecondary · retrieved 2026-08-01
- InCrypthosSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Seedify hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/seedifyhttps://itokenly.com/hacks/seedifyPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.