• bitcoinBitcoin (BTC) $ 113,200.00
  • ethereumEthereum (ETH) $ 4,013.23
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.65
  • bnbBNB (BNB) $ 1,114.23
  • solanaWrapped SOL (SOL) $ 198.80
  • usd-coinUSDC (USDC) $ 0.999893
  • staked-etherLido Staked Ether (STETH) $ 4,012.49
  • dogecoinDogecoin (DOGE) $ 0.195444
  • tronTRON (TRX) $ 0.296859
  • cardanoCardano (ADA) $ 0.650516
  • wrapped-stethWrapped stETH (WSTETH) $ 4,884.80
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,078.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,331.75
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 49.29
  • chainlinkChainlink (LINK) $ 18.13
  • bitcoin-cashBitcoin Cash (BCH) $ 552.18
  • wrapped-eethWrapped eETH (WEETH) $ 4,331.60
  • stellarStellar (XLM) $ 0.323402
  • ethena-usdeEthena USDe (USDE) $ 0.999227
  • suiSui (SUI) $ 2.54
  • usdsUSDS (USDS) $ 1.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999956
  • wethWETH (WETH) $ 4,011.27
  • leo-tokenLEO Token (LEO) $ 9.61
  • hedera-hashgraphHedera (HBAR) $ 0.198494
  • avalanche-2Avalanche (AVAX) $ 19.74
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 113,165.00
  • litecoinLitecoin (LTC) $ 98.47
  • usdt0USDT0 (USDT0) $ 1.00
  • moneroMonero (XMR) $ 341.86
  • whitebitWhiteBIT Coin (WBT) $ 42.63
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • the-open-networkToncoin (TON) $ 2.32
  • zcashZcash (ZEC) $ 331.02
  • crypto-com-chainCronos (CRO) $ 0.149321
  • mantleMantle (MNT) $ 1.60
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • polkadotPolkadot (DOT) $ 3.11
  • daiDai (DAI) $ 0.999625
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.151520
  • bittensorBittensor (TAO) $ 429.01
  • memecoreMemeCore (M) $ 2.30
  • uniswapUniswap (UNI) $ 6.37
  • aaveAave (AAVE) $ 231.57
  • okbOKB (OKB) $ 163.82
  • susdssUSDS (SUSDS) $ 1.07
  • ethenaEthena (ENA) $ 0.461356
  • bitget-tokenBitget Token (BGB) $ 4.71
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • pepePepe (PEPE) $ 0.000007
  • nearNEAR Protocol (NEAR) $ 2.30
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 246.28
  • paypal-usdPayPal USD (PYUSD) $ 0.999934
  • ethereum-classicEthereum Classic (ETC) $ 16.16
  • aptosAptos (APT) $ 3.42
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,010.92
  • ondo-financeOndo (ONDO) $ 0.738486
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.58
  • pi-networkPi Network (PI) $ 0.270914
  • aster-2Aster (ASTER) $ 1.09
  • falcon-financeFalcon USD (USDF) $ 0.997338
  • tether-goldTether Gold (XAUT) $ 4,020.33
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.197904
  • worldcoin-wldWorldcoin (WLD) $ 0.881422
  • usdtbUSDtb (USDTB) $ 0.999278
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,601.34
  • arbitrumArbitrum (ARB) $ 0.323741
  • pump-funPump.fun (PUMP) $ 0.005019
  • binance-staked-solBinance Staked SOL (BNSOL) $ 215.08
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 49.41
  • kucoin-sharesKuCoin (KCS) $ 13.49
  • htx-daoHTX DAO (HTX) $ 0.000002
  • gatechain-tokenGate (GT) $ 14.79
  • internet-computerInternet Computer (ICP) $ 3.09
  • official-trumpOfficial Trump (TRUMP) $ 8.32
  • hash-2Provenance Blockchain (HASH) $ 0.032520
  • algorandAlgorand (ALGO) $ 0.184862
  • story-2Story (IP) $ 5.00
  • kaspaKaspa (KAS) $ 0.058504
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,239.72
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,236.18
  • cosmosCosmos Hub (ATOM) $ 3.12
  • vechainVeChain (VET) $ 0.016943
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,306.45
  • wbnbWrapped BNB (WBNB) $ 1,113.73
  • jupiter-exchange-solanaJupiter (JUP) $ 0.424815
  • skySky (SKY) $ 0.058469
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 113,220.00
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 4,018.36
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.021115
  • bfusdBFUSD (BFUSD) $ 0.999893
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • flare-networksFlare (FLR) $ 0.016673
  • render-tokenRender (RENDER) $ 2.46
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,263.47
  • sei-networkSei (SEI) $ 0.198027
  • filecoinFilecoin (FIL) $ 1.63
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999674
  • nexoNEXO (NEXO) $ 1.13
  • bonkBonk (BONK) $ 0.000015
  • xdce-crowd-saleXDC Network (XDC) $ 0.061458
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,811.00
  • immutable-xImmutable (IMX) $ 0.535924
  • morphoMorpho (MORPHO) $ 1.99
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997827
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,321.90
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 227.96
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.52
  • spx6900SPX6900 (SPX) $ 1.05
  • global-dollarGlobal Dollar (USDG) $ 0.999987
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 113,131.00
  • ripple-usdRipple USD (RLUSD) $ 0.999745
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.60
  • aerodrome-financeAerodrome Finance (AERO) $ 0.976250
  • clbtcclBTC (CLBTC) $ 113,071.00
  • celestiaCelestia (TIA) $ 1.02
  • optimismOptimism (OP) $ 0.445885
  • injective-protocolInjective (INJ) $ 8.59
  • lido-daoLido DAO (LDO) $ 0.929999
  • fasttokenFasttoken (FTN) $ 1.91
  • msolMarinade Staked SOL (MSOL) $ 264.86
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • blockstackStacks (STX) $ 0.447809
  • ousgOUSG (OUSG) $ 113.09
  • doublezeroDoubleZero (2Z) $ 0.224481
  • curve-dao-tokenCurve DAO (CRV) $ 0.535796
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.87
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 4,257.24
  • flokiFLOKI (FLOKI) $ 0.000073
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,013.25
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998733
  • plasmaPlasma (XPL) $ 0.361079
  • the-graphThe Graph (GRT) $ 0.064403
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.260871
  • tbtctBTC (TBTC) $ 112,698.00
  • pyth-networkPyth Network (PYTH) $ 0.113903
  • kaiaKaia (KAIA) $ 0.109004
  • tezosTezos (XTZ) $ 0.597744
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,011.43
  • stader-ethxStader ETHx (ETHX) $ 4,304.14
  • gtethGTETH (GTETH) $ 4,010.79
  • sonic-3Sonic (S) $ 0.162349
  • dashDash (DASH) $ 48.42
  • iotaIOTA (IOTA) $ 0.146356
  • chainopera-aiChainOpera AI (COAI) $ 3.05
  • beldexBeldex (BDX) $ 0.078787
  • usdaiUSDai (USDAI) $ 1.02
  • conflux-tokenConflux (CFX) $ 0.110656
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999893
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999947
  • pendlePendle (PENDLE) $ 3.28
  • newton-projectAB (AB) $ 0.006548
  • ether-fiEther.fi (ETHFI) $ 0.969810
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,415.96
  • usual-usdUsual USD (USD0) $ 0.998054
  • dogwifcoindogwifhat (WIF) $ 0.541159
  • swethSwell Ethereum (SWETH) $ 4,425.12
  • theta-tokenTheta Network (THETA) $ 0.534490
  • the-sandboxThe Sandbox (SAND) $ 0.214819
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 113,229.00
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.73
  • starknetStarknet (STRK) $ 0.120483
  • wrapped-hypeWrapped HYPE (WHYPE) $ 48.99
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.25
  • humanityHumanity (H) $ 0.284316
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • galaGALA (GALA) $ 0.010961
  • jasmycoinJasmyCoin (JASMY) $ 0.010443
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.195227
  • raydiumRaydium (RAY) $ 1.85
  • true-usdTrueUSD (TUSD) $ 0.998428
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,007.51
  • myx-financeMYX Finance (MYX) $ 2.57
  • bittorrentBitTorrent (BTT) $ 0.00000050
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,176.68
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,327.53
  • vaultaVaulta (A) $ 0.288083
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.29
  • decentralandDecentraland (MANA) $ 0.238454
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 49.65
  • heliumHelium (HNT) $ 2.42
  • bitcoin-svBitcoin SV (BSV) $ 22.53
  • swissborgSwissBorg (BORG) $ 0.453830
  • usddUSDD (USDD) $ 1.00
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,318.84
  • flowFlow (FLOW) $ 0.272618
  • sun-tokenSun Token (SUN) $ 0.022681
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,012.83
  • syrupMaple Finance (SYRUP) $ 0.387263
  • ghoGHO (GHO) $ 0.999619
  • jito-governance-tokenJito (JTO) $ 1.07
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000002
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.06
  • frax-etherFrax Ether (FRXETH) $ 3,967.52

$145K Lost as Hackers Use Merkl to Launch Unverified DeFi Scams

0 2

$145K Lost as Hackers Use Merkl to Launch Unverified DeFi Scams

Hackers have found a new way to exploit decentralized finance (DeFi) users. This time, they used Merkl, a one-stop DeFi incentive platform, to create fake, unverified campaigns and drain users’ deposits. The scam targeted users on Sonic through the Euler protocol. It has already caused losses of more than $145,000.

Hackers Create Fake High-Yield Campaigns

According to DeFi user YAM, a bad actor took advantage of Merkl’s open setup to create fake campaigns. That appeared to offer triple-digit APR returns. The scam invited users to deposit USDC into what looked like a legitimate Euler vault on Sonic. However, once users deposited their funds, the attacker drained them completely.

吴说获悉,据 DeFi 玩家 YAM,黑客正在利用一站式 DeFi 协议 Merkl 创建未验证的活动以欺诈用户存款,如近期黑客通过在 Sonic 上创建三位数 APR 激励以诱导用户将 USDC 存入 Euler Vault,然后再抽干所有存款。由于 Euler…

— 吴说区块链 (@wublockchain12) October 29, 2025

Because Euler Finance is a permissionless protocol, anyone can deploy markets without approval. The attacker used this feature to launch a fake market. Using a token called scUSD as collateral and USDC as debt. They then manipulated the oracle price, a key data feed used in DeFi, setting it to an absurd $1 million per token. This allowed them to borrow 700,000 USDC against a single scUSD. This effectively gives them complete control of the vault’s funds.

How the Scam Worked

Once the fake market was live, the attacker launched an unverified campaign on Merkl. He is promoting extremely high yields to attract deposits. Users who deposited USDC into the campaign had their funds borrowed, swapped into ETH. Then transferred to the RAILGUN Project, a privacy protocol often used to hide transactions.

On-chain data shows the main operator’s wallet address as 0x8ba913e…, with funds eventually sent to 0xa86399… before disappearing into RAILGUN. Interestingly, one user, identified as 0xc0f8fe… managed to withdraw their deposit before the attacker drained it. Likely because the hacker was not actively monitoring the vault.

Reactions From the DeFi Community

Following the discovery, YAM urged users to be cautious when interacting with unverified Merkl campaigns. They also called on Merkl’s team to make it more difficult to deposit into such campaigns by adding stronger pop-up warnings.

Michael Bentley, co-founder and CEO of Euler Labs, responded by confirming. That the vault in question was clearly marked as unverified and labeled a security risk. He noted that the Euler website only allows access to unverified vaults after users manually toggle an option acknowledging the risk. “We’re now permanently blocking all links to this particular vault to prevent further use,” Bentley added.

Community members also raised questions about how DeFi users can verify if a market’s oracle is legitimate. YAM explained that oracles provide real-world price data to DeFi apps. They are often controlled by the market’s curators and must be set up carefully. A small mistake, such as an incorrect decimal or an unsecured multisig, can open doors to major exploits like this one.

Calls for Stronger Safeguards

The incident highlights a recurring issue in DeFi. The balance between permissionless innovation and user safety. Platforms like Merkl and Euler allow anyone to create or join markets freely. But that openness also gives attackers room to act. While projects clearly mark unverified campaigns. The growing number of scams shows that warnings alone may not be enough.

Users are now calling for more friction, such as mandatory verification checks or extra confirmations, to protect deposits. Currently, experts are advising users to interact only with verified campaigns and double-check contract details before depositing funds. The $145,000 exploit serves as another reminder that even in DeFi’s open world, caution is the best defense.

Source

Leave A Reply

Your email address will not be published.