T
iTokenly

Texture hack — July 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 9, 2025
Target typeLending protocol
Loss$2,200,000Price at time of incident
Recovered$1,980,000
MethodAccess control flawThe vault rebalance path did not verify ownership of every account passed to it. Certora, which had audited the Vaults contract, said the missing permissions check was not caught in its manual review; an attacker could hand the rebalance instruction accounts under their own control and have the vault route USDC to their wallet. Only the USDC vault was affected. The fix validates ownership of all accounts involved in a rebalance before executing it.
ChainsSolana
Audited beforehandCertora
OutcomeSettled as bug bounty

What happened

Texture, a lending protocol on Solana, detected on 9 July 2025 that its Vaults contract had been compromised and 2.2 million USDC taken.

The fault was in the vault rebalance path. Certora, which had audited the contract, published an account of the incident saying a permissions check was missing and had not been caught during its manual review. The rebalance instruction did not verify ownership of every account handed to it, so an attacker could supply accounts under their own control and have the vault move funds to their wallet. Only the USDC vault was affected. Texture disabled withdrawals, convened a war room with Certora, and within minutes developed and validated a fix that defensively checks ownership of all accounts involved in a rebalance before executing it.

Texture then offered the attacker a 10 percent bounty, roughly $220,000, to keep in exchange for returning the other 90 percent, setting a deadline of 18:00 UTC on 11 July and stating that failure to comply would mean referral to law enforcement. The attacker returned about $1.98 million before the deadline and retained the bounty. Texture said the attacker had fulfilled their side of the arrangement and that it would not pursue the matter further, and Certora reported the protocol remained well funded.

The attacker was not identified and no charges followed. Figures for the loss were consistent across Texture's own disclosure and subsequent reporting at 2.2 million USDC, with 90 percent returned.

Law enforcement

Texture said it would refer the matter to law enforcement if the bounty deadline passed. The funds were returned in time and Texture said it would not pursue the matter further. No public case or charges.

Sources

  1. CertoraPrimary · retrieved 2026-08-01
  2. CryptopolitanSecondary · retrieved 2026-08-01
  3. Web3 Is Going GreatSecondary · retrieved 2026-08-01

Official post-mortem: https://www.certora.com/blog/rapid-response-full-recovery-certora-and-texture-a

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Texture hack — July 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/texture
https://itokenly.com/hacks/texture

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.