TLDR
This weeks notable DeFi security incidents: Unleash Protocol (~$3.9M), Flow network (~$3.9M), and Polymarket account drains via a third?party auth provider.
- Unleash Protocol lost about $3.9M following a malicious governance upgrade, per a security alert and post?mortem details (PeckShield alert, analysis).
- Flows execution layer vulnerability enabled roughly $3.9M in assets to move off?network; rollback plans were revised after community pushback (security update, Flow exploit overview).
- Polymarket confirmed limited account drains caused by a third?party authentication vulnerability; the core protocol remained secure (platform notice and report).
Deep Dive
1. Unleash Protocol
Attackers exploited governance controls to push an unauthorized contract upgrade, bypassing multisig permission checks and draining funds (WIP, USDC, WETH, stIP, vIP). The exploiter bridged proceeds to Ethereum and laundered around 1,337.1 ETH via Tornado Cash, and the team paused operations for investigation (alert, governance failure analysis).
- Operations were paused; users were told not to interact with contracts while remediation proceeds (analysis).
- The vector centered on admin permission enforcement and upgrade paths, not a user wallet compromise (alert).
Governance and upgrade safety are critical. If you interacted with Unleash, consider revoking approvals and avoid contracts until official remediation is complete.
2. Flow Network
A vulnerability in Flows execution layer allowed an attacker to move assets off?network (including PYUSD, WBTC, ETH), with subsequent swaps and laundering via Thorchain and Chainflip. An initial rollback proposal faced strong criticism and was replaced with targeted remediation to destroy fraudulently minted tokens while preserving legitimate activity (security summary, overview).
- Approximate losses were $3.9M; exchanges and stablecoin issuers were asked to help contain funds (overview).
- The network moved from a global rollback to a narrower fix after bridge operators and exchanges flagged trust and balance?integrity risks (overview).
Cross?chain flows amplify impact. If you hold bridged assets linked to Flow, watch for exchange freezes and targeted remediation updates before moving funds.
3. Polymarket Account Drains
Polymarket reported unauthorized drains tied to a third?party authentication provider, mainly affecting email?based wallet logins; the core protocol stayed secure and the vulnerability was fixed (platform report).
- The impact was limited to accounts using the affected auth pathway; Polymarket emphasized no protocol?level compromise (platform report).
- Users were advised to secure access methods and avoid vulnerable login routes.
Third?party auth stacks can be a weak link. Prefer native or hardware wallets, and review connected apps and permissions regularly.
Conclusion
This weeks incidents share a theme: governance pathways (Unleash), execution?layer vulnerabilities (Flow), and external auth stacks (Polymarket) can all be exploited even when core contracts seem sound. The practical takeaway is to monitor official notices, limit contract approvals, and avoid risky login flows. If you need, I can check approvals for a specific address or pull fresh incident advisories for protocols you use.
