Unleash Protocol Hit by $3.9M Hack—Funds Laundered via Tornado Cash
Unleash Protocol lost $3.9 million after a multisig exploit enabled unauthorized withdrawals. The attacker bridged funds to Ethereum and used Tornado Cash to hide the trail. Operations are suspended and users are advised to avoid the protocol.
Unleash Protocol experienced a major security breach on December 30, 2025, resulting in the loss of approximately $3.9 million. The attacker exploited a vulnerability in the protocol’s multi-signature governance system, gaining unauthorized administrative access and executing an unapproved contract upgrade. This allowed the withdrawal of assets including WIP, USDC, WETH, stIP, and vIP. The stolen funds were bridged to Ethereum and deposited into Tornado Cash in multiple transactions to obscure their origin. The exploit affected only Unleash Protocol’s contracts, with no evidence of compromise to the underlying Story Protocol infrastructure, which remained operational. Following the incident, Unleash Protocol suspended all operations, initiated a full investigation, and advised users not to interact with its contracts. The event underscores ongoing security risks in DeFi, particularly regarding multisig governance and cross-chain bridges, and has prompted calls for improved security audits and stricter protocol controls.