According to ChainCatcher, as monitored by Paidun, CrediX suffered a security vulnerability attack today, with hackers carrying out the attack by misusing an administrator account with multiple management permissions. This account possessed permissions such as: POOL_ADMIN (fund pool administrator), BRIDGE (cross-chain bridge permissions), ASSET_LISTING_ADMIN (asset listing administrator), EMERGENCY_ADMIN (emergency administrator), RISK_ADMIN (risk control administrator).
The attacker utilized the BRIDGE permissions to steal or borrow assets from the fund pool, with estimated losses of around $4.5 million. This also included the minting of forged (without real asset backing) acUSDC tokens (Credix Market Sonic USDC).




