Mozaic Hack

REPORTED LOSS $2.1M
Medium Access Control arbitrum

What happened

On March 15, 2024, Mozaic Finance lost assets after a private-key compromise gave an attacker access to its vaults. CertiK estimated $2.1 million stolen, while Halborn estimated $2.4 million. Reports described funds frozen at MEXC, not a verified completed return.

Technical Root Cause

A compromised privileged key retained unilateral access to a legacy vault security module.

Case & protocol details

Classification Yield Aggregator / Key Compromise
Protocol Type Yield
Implementation language Solidity
Official Website mozaic.finance/
Protocol Twitter/X @Mozaic_Fi

How it happened

  1. The attacker obtained a core team member's private keys, according to Halborn's account.
  2. The keys authorized functions in a still-active security module with vault access.
  3. Stablecoins were transferred out and sent to MEXC and Binance.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.