Stream Finance Hack
Incident Overview
On November 4, 2025, Stream Finance disclosed that an external fund manager overseeing Stream funds lost approximately $93 million in assets, triggering a cascade of collateral damage estimated at $285 million across the DeFi ecosystem. The incident caused Stream's synthetic tokens (xUSD, xBTC, xETH) to lose their pegs, with xUSD plummeting from $1.3 to $0.3, affecting numerous lending platforms and treasury positions.
The $93 million loss was disclosed by an external fund manager responsible for overseeing Stream fund assets, though specific technical details of how the funds were lost remain unclear. The incident had catastrophic ripple effects due to Stream's $285 million total debt position across multiple DeFi lending platforms. The collapse of xUSD triggered a systemic crisis affecting collateral loops and lending positions: deUSD issuer Elixir had provided Stream with a $68 million USDC loan (representing 65% of deUSD's collateral), and scUSD from Treeve was trapped in complex collateral loops across Mithras, Silo, and Euler platforms backed by xUSD.
Stream's debt distribution includes TelosC ($123.6M), Elixir ($68M), MEV Capital ($25.4M), Varlamore ($19.1M), Re7 ($14.2M), and several smaller lenders. Stream immediately suspended all withdrawals and deposits, engaged law firm Perkins Coie to lead the investigation, and began withdrawing all liquid assets. The synthetic tokens xUSD, xBTC, and xETH used as collateral on Euler, Silo, Morpho, and Sonic platforms remained at risk.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Stream Finance, these are the critical security checks that could have prevented this incident (November 2025).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Post-Incident Timeline
-
2025-11-06
Following the November 4 Stream Finance hack that resulted in $93 million in direct losses and $285 million in collateral damage, the ripple effects continue to destabilize the DeFi ecosystem. Elixir Protocol announced it would discontinue support for its deUSD stablecoin after Stream's xUSD collapsed to $0.17-0.20, having redeemed approximately 80% of deUSD at 1:1 in USDC. Additionally, Stable Labs' USDX stablecoin lost its peg on November 6, plummeting over 60% to $0.30, potentially triggered by cascade liquidations from the Balancer hack and Stream Finance fallout, with Stable Labs owing $68 million to Elixir as part of Stream's total $285 million debt.
Sources & References
Learn to Prevent the Next Stream Finance
The Stream Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.