AlexLab Hack
What happened
June 6, 2025 – Bitcoin DeFi project AlexLab was exploited for over $16.1M due to a critical flaw in its token listing logic. Fake tokens were used to drain multiple vaults, despite recent audits.
An attacker exploited AlexLab’s self-listing mechanism by deploying a malicious token with a fake transfer function. The token passed AlexLab’s flawed verification checks and was granted vault permissions. By creating a liquidity pool and enabling farming, the attacker triggered vault-level transfers via a single swap-x-for-y call, siphoning out millions in STX, sBTC, aBTC, USDT, USDC, WBTC, and ALEX tokens.
Despite AlexLab blaming Stacks' failure handling, the root cause was insecure access control in AlexLab's vault contract. Officially, AlexLab claimed $8.3M in losses and promised reimbursement, but onchain analysis shows the actual loss exceeded $16.1M.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- report Report unchainedcrypto.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.