Please Register !
Fuzzland, a well-known smart contract auditing platform, has revealed that a former team member orchestrated a major breach against Bedrock’s UniBTC protocol — resulting in $2 million in losses. The shocking disclosure came through a detailed transparency report published in June 2025.
Please Register !
According to Fuzzland, the breach took place in September 2024 and was made possible due to:
-
Insider access — The attacker had access to internal systems.
-
Malware implantation — Malicious code was secretly deployed on developer machines.
-
Advanced persistent threat tactics — Techniques designed for long-term covert operations.
-
Supply chain attacks — The codebase was compromised at a foundational level.
-
Social engineering — Human manipulation led to sensitive information leaks.
Please Register !
Please Register !
Please Register !
Fuzzland stated that the flaw in the UniBTC protocol was initially detected internally but dismissed due to false positives — a costly mistake. The vulnerability was also flagged in an external
Please Register !
Fuzzland has since fully compensated Bedrock for the $2 million loss. Additionally, they’ve:
-
Partnered with ZeroShadow for a joint investigation
Please Register !
-
Involved Chinese authorities and the FBI for criminal investigation
Please Register !
Please Register !
-
Collaborated with Seal 911 and SlowMist to improve global Web3 security protocols
Please Register !
Please Register !
Please Register !
Bedrock, known for its multi-asset restaking solutions like UniBTC, UniETH, and UniLOTX, saw one of its main products exploited. On September 27, 2024, the platform confirmed that $2 million in liquidity was drained from UniBTC pools on its DEX.
<foto>
Please Register !
Please Register !
Please Register !
Please Register !
This revelation comes amid a broader trend: a surge in social engineering and phishing-based crypto hacks. According to a
Please Register !
CertiK’s co-founder, Ronghui Gu, noted that hackers are increasingly abandoning direct code exploits in favor of manipulating people — a shift in strategy that’s proving alarmingly effective.
Please Register !
This incident highlights several urgent lessons:
-
Internal security is just as crucial as external safeguards.
-
False positives in vulnerability reports must be revisited with care.
-
Malware detection and employee monitoring tools should be prioritized in security stacks.
-
The importance of collaboration between security firms and law enforcement in tackling insider threats cannot be understated.
