Berally Hack

Reported loss $90K
Berachain
Private Key Compromised (Unknown Method)

What happened

On March 15, 2025, Berally (Ethereum) was hacked due to a compromised deployer key, leading to the dumping of all vesting tokens and the draining of the liquidity pool.

The attacker gained access to Berally’s deployer key, allowing them to transfer and sell vesting tokens meant for controlled distribution. This mass sell-off drained the liquidity pool, likely crashing the token price. However, the dApp contracts remain unaffected, and users were advised to revoke access from the dApp and staking contracts as a precaution.

The breach suggests either private key leakage or an internal security lapse, enabling unauthorized transactions.

Protocol details

Classification Infrastructure / Other / Key Compromise
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol links @Berally_io

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.