T
iTokenly

Unleash Protocol hack — December 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedDecember 30, 2025
Target typeOther
Loss$3,900,000Price at time of incident
MethodAccess control flawAn externally owned address obtained administrative control through the project's multisig governance and pushed an unauthorised upgrade to a protocol contract, which allowed asset withdrawals outside approved governance procedures. The team did not publish whether the underlying cause was signer key compromise or multisig misconfiguration.
ChainsOther, Ethereum
OutcomeUnresolved

What happened

Unleash Protocol, an intellectual-property tokenisation and licensing platform built on the Story blockchain, was drained on 30 December 2025. In its own statement the team said an externally owned address "gained administrative control via Unleash's multisig governance" and used it to carry out an unauthorised contract upgrade, which permitted withdrawals of user assets outside approved governance procedures. WIP, USDC, WETH, stIP and vIP tokens were taken.

The team did not publish a root-cause finding for how the external address obtained multisig authority, so it is not publicly established whether signer keys were compromised or the multisig was misconfigured. Unleash said the incident was confined to its own governance framework, adding that there was "no evidence of compromise to Story Protocol contracts, validators, or underlying infrastructure."

PeckShield and CertiK tracked the outflow. CertiK flagged transfers to an externally owned account created through a SafeProxyFactory contract. PeckShield recorded the proceeds being bridged to Ethereum and deposited into Tornado Cash in chunks of up to 100 ETH, following an initial 0.1 ETH test deposit. The total was reported as 1,337.1 ETH, worth about $3.9 million at the time. The Block's headline rounded the laundered sum to $4 million; no materially lower figure has been published.

Unleash paused all operations and told users not to interact with its contracts pending an investigation by outside security and forensic specialists. No funds have been reported recovered, no investigator has publicly attributed the theft to a named actor or group, and no arrests have been reported.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. The Crypto TimesSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Unleash Protocol hack — December 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/unleash-protocol
https://itokenly.com/hacks/unleash-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.