Alchemix patched a critical vulnerability in TokeAutoETH that could have exposed $3M to theft, paying TrustSec a $300K bug bounty.
Security & Exploits ·
Alchemix addressed a critical vulnerability in its TokeAutoETH contract that could have enabled theft of approximately $3 million in assets. The protocol engaged security firm TrustSec to identify and verify the flaw, awarding a $300,000 bug bounty upon successful disclosure and remediation.
The vulnerability existed within smart-contract code governing automated token handling in the platform's yield-generation mechanics. By exploiting this flaw, an attacker could have redirected or drained deposited funds without authorization. Crypto theft typically targets the private keys and credentials that control assets rather than coins directly, since blockchain transactions are irreversible once confirmed and no central authority can reverse them.
The patch was deployed after TrustSec's discovery and before any active exploitation occurred. No funds were lost, and no timeline for the vulnerability's initial introduction or the duration of exposure has been disclosed. It remains unclear whether the flaw was identified through routine auditing or third-party disclosure, or whether similar vulnerabilities may exist elsewhere in Alchemix's codebase.