AlexLab Hack
Incident Overview
June 6, 2025 – Bitcoin DeFi project AlexLab was exploited for over $16.1M due to a critical flaw in its token listing logic. Fake tokens were used to drain multiple vaults, despite recent audits.
An attacker exploited AlexLab’s self-listing mechanism by deploying a malicious token with a fake transfer function. The token passed AlexLab’s flawed verification checks and was granted vault permissions. By creating a liquidity pool and enabling farming, the attacker triggered vault-level transfers via a single swap-x-for-y call, siphoning out millions in STX, sBTC, aBTC, USDT, USDC, WBTC, and ALEX tokens.
Despite AlexLab blaming Stacks' failure handling, the root cause was insecure access control in AlexLab's vault contract. Officially, AlexLab claimed $8.3M in losses and promised reimbursement, but onchain analysis shows the actual loss exceeded $16.1M.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to AlexLab, these are the critical security checks that could have prevented this incident (June 2025).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://rekt.news/alexlab-rekt2
- 02
- 03
Learn to Prevent the Next AlexLab
The AlexLab hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.