Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Centralized Control Comes at a Price: UXLINK’s $11 Million Hack Reveals the Overlooked Dangers of Multisig

Centralized Control Comes at a Price: UXLINK’s $11 Million Hack Reveals the Overlooked Dangers of Multisig

Bitget-RWA2025/09/24 09:46
By:Coin World

- UXLINK's multisig wallet was hacked via a delegateCall vulnerability, enabling unauthorized minting of 10 trillion tokens and draining $11.3M in assets. - The attack caused UXLINK's token price to drop 70% and exposed centralized governance risks in Ethereum-based multisig systems. - UXLINK responded by freezing suspicious transactions, planning a token swap, and developing a fixed-supply smart contract to restore ecosystem stability. - The incident highlights critical vulnerabilities in centralized mult

Centralized Control Comes at a Price: UXLINK’s $11 Million Hack Reveals the Overlooked Dangers of Multisig image 0

UXLINK, a Web3 social platform, recently experienced a major security incident that revealed weaknesses in its multi-signature wallet setup and sparked debate over centralization risks in Ethereum smart contracts. On September 22, 2025, an attacker exploited a delegateCall flaw, gaining administrative access to the wallet. This breach enabled the attacker to create roughly 10 trillion UXLINK tokens—far surpassing the existing supply—and siphon off $11.3 million in assets, including stablecoins, ETH, and WBTC The Block, [ 1 ]. The unauthorized token creation led to a price crash of more than 70%, dropping from $0.30 to $0.09 and wiping out close to $70 million in market value within a few hours CoinPedia, [ 3 ].

The attacker took advantage of a serious governance weakness in the multisig wallet, allowing them to remove current administrators, assign a new owner, and carry out large token sales on decentralized exchanges. Blockchain analysis showed the hacker swapped the stolen UXLINK tokens for 6,732 ETH—worth $28.1 million—across six different wallets. Although the attacker quickly tried to cash out, most of their funds were frozen by exchanges, which helped limit further damage The Block, [ 1 ]. This event highlights the dangers of centralized control in multisig wallets, where a single vulnerability can jeopardize the entire system.

In response, UXLINK worked closely with exchanges to freeze suspicious deposits and temporarily suspend trading. The team also revealed plans for a token swap to address the unauthorized minting and stabilize the platform. A new smart contract with a capped supply is being developed to prevent similar inflation in the future Coin Telegraph, [ 2 ]. While assuring users that individual wallets were not compromised, the team advised everyone to confirm transactions through official sources. Interestingly, during the exploit, the attacker themselves became a victim of a phishing scam by the Inferno Drainer group, losing over 542 million of the stolen tokens CoinPedia, [ 3 ].

This breach has broader consequences for Ethereum’s smart contract ecosystem. While multisig wallets are often seen as a security feature, this case shows they can become single points of failure if governance is too centralized. The delegateCall vulnerability exploited here underscores the importance of thorough code audits and more decentralized governance structures. The incident has also renewed discussions about the dangers of permissioned minting functions, even in projects that claim to be decentralized.

Both market observers and regulators are now paying closer attention to how blockchain projects balance security and decentralization. UXLINK’s planned token swap and its cooperation with blockchain security firms like PeckShield and Hacken are steps toward regaining trust, but the incident stands as a warning for projects that depend on centralized multisig arrangements. As UXLINK works to recover, the

community will likely push for greater transparency, stronger smart contract audits, and more decentralized governance to reduce the risk of similar attacks in the future.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

CandyBomb x BLESS: Trade to share 4,300,000 BLESS!

Bitget Announcement2025/09/24 07:30

CandyBomb x RIVER: Trade to share 127,000 RIVER!

Bitget Announcement2025/09/24 07:30

Bitget Spot Cross Margin adds AVNT/USDT、SOMI/USDT

Bitget Announcement2025/09/24 03:27

New spot margin trading pair — 0G/USDT!

Bitget Announcement2025/09/23 10:18