Unleash Protocol hack — December 2025
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | December 30, 2025 |
| Target type | Other |
| Loss | $3,900,000Price at time of incident |
| Method | Access control flawAn externally owned address obtained administrative control through the project's multisig governance and pushed an unauthorised upgrade to a protocol contract, which allowed asset withdrawals outside approved governance procedures. The team did not publish whether the underlying cause was signer key compromise or multisig misconfiguration. |
| Chains | Other, Ethereum |
| Outcome | Unresolved |
What happened
Unleash Protocol, an intellectual-property tokenisation and licensing platform built on the Story blockchain, was drained on 30 December 2025. In its own statement the team said an externally owned address "gained administrative control via Unleash's multisig governance" and used it to carry out an unauthorised contract upgrade, which permitted withdrawals of user assets outside approved governance procedures. WIP, USDC, WETH, stIP and vIP tokens were taken.
The team did not publish a root-cause finding for how the external address obtained multisig authority, so it is not publicly established whether signer keys were compromised or the multisig was misconfigured. Unleash said the incident was confined to its own governance framework, adding that there was "no evidence of compromise to Story Protocol contracts, validators, or underlying infrastructure."
PeckShield and CertiK tracked the outflow. CertiK flagged transfers to an externally owned account created through a SafeProxyFactory contract. PeckShield recorded the proceeds being bridged to Ethereum and deposited into Tornado Cash in chunks of up to 100 ETH, following an initial 0.1 ETH test deposit. The total was reported as 1,337.1 ETH, worth about $3.9 million at the time. The Block's headline rounded the laundered sum to $4 million; no materially lower figure has been published.
Unleash paused all operations and told users not to interact with its contracts pending an investigation by outside security and forensic specialists. No funds have been reported recovered, no investigator has publicly attributed the theft to a named actor or group, and no arrests have been reported.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Unleash Protocol hack — December 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/unleash-protocolhttps://itokenly.com/hacks/unleash-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.