Fuzzland Reveals Ex-Employee Behind $2M Bedrock UniBTC Exploit



Fuzzland’s Transparency Report: Inside Job Behind $2 Million Exploit

Smart contract analytics platform Fuzzland has revealed that a former employee was behind a $2 million exploit that targeted Bedrock’s UniBTC protocol in September 2024.



Details of the Exploit

In a newly released transparency report, Fuzzland disclosed that the insider leveraged social engineering tactics, supply chain attacks, and advanced persistent threat techniques to obtain sensitive data, enabling the attack. The attacker exploited a vulnerability in UniBTC, which had been discussed internally during an emergency response call.

The company further explained that the ex-employee had inserted malicious code to create backdoors in engineering workstations, which remained undetected for weeks. This access allowed the attacker to intercept sensitive information and exploit the vulnerability first highlighted in a Dedaub report.

Fuzzland admitted that although they had detected the vulnerability prior to the attack, it was deprioritized due to false positive noise.

Compensation and Investigation Efforts

Compensation to Bedrock

The smart contract security platform has compensated Bedrock for the damages incurred and initiated a joint investigation with security firm ZeroShadow.

Collaboration with Authorities and Security Firms

Fuzzland has filed reports with Chinese law enforcement and the FBI. Additionally, they are collaborating with Seal 911 and SlowMist to improve industry-wide security standards.



Despite the $2 million loss due to the incident, Fuzzland confirmed that no client or customer data was compromised, as the breach was confined to a separate internal environment.

See also  SUI Chart Pattern Confirmation Sets $3.89 Price Goal

Impact on Bedrock

Bedrock, a multi-asset liquid restaking protocol that offers products like UniBTC, UniETH, and UnilOTX, confirmed the exploitation of its UniBTC product on September 27. The attacker siphoned $2 million in liquidity from its decentralized exchange pools. However, Bedrock’s total value locked (TVL) increased from $240 million in September 2024 to $535 million by June 2025, according to DefiLlama.

Rising Trend in Crypto Attacks

This report surfaces amidst a growing trend where hackers shift focus from smart contract vulnerabilities to social engineering schemes. On June 4, blockchain security firm CertiK reported that more than $2.1 billion has been stolen in crypto-related attacks in 2025.

Most of these losses stem from phishing attacks and wallet compromises. CertiK co-founder Ronghui Gu indicated that the uptick in social engineering attacks signifies a change in hackers’ strategies.


Image Credit: cointelegraph.com

Hot Topics

Related Articles

bitcoin
Bitcoin (BTC) $ 118,270.69
ethereum
Ethereum (ETH) $ 3,771.49
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 795.17
xrp
XRP (XRP) $ 3.20
cardano
Cardano (ADA) $ 0.828476
usd-coin
USDC (USDC) $ 1.00
matic-network
Polygon (MATIC) $ 0.236822
binance-usd
BUSD (BUSD) $ 0.997766
dogecoin
Dogecoin (DOGE) $ 0.238938
okb
OKB (OKB) $ 48.25
polkadot
Polkadot (DOT) $ 4.18
shiba-inu
Shiba Inu (SHIB) $ 0.000014
tron
TRON (TRX) $ 0.320619
uniswap
Uniswap (UNI) $ 10.60
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 118,154.66
dai
Dai (DAI) $ 1.00
litecoin
Litecoin (LTC) $ 114.83
staked-ether
Lido Staked Ether (STETH) $ 3,767.73
solana
Solana (SOL) $ 186.57
avalanche-2
Avalanche (AVAX) $ 25.00
chainlink
Chainlink (LINK) $ 18.68
cosmos
Cosmos Hub (ATOM) $ 4.80
the-open-network
Toncoin (TON) $ 3.32
ethereum-classic
Ethereum Classic (ETC) $ 23.09
leo-token
LEO Token (LEO) $ 8.99
filecoin
Filecoin (FIL) $ 2.69
bitcoin-cash
Bitcoin Cash (BCH) $ 570.21
monero
Monero (XMR) $ 322.17