Gate Square “Creator Certification Incentive Program” — Recruiting Outstanding Creators!
Join now, share quality content, and compete for over $10,000 in monthly rewards.
How to Apply:
1️⃣ Open the App → Tap [Square] at the bottom → Click your [avatar] in the top right.
2️⃣ Tap [Get Certified], submit your application, and wait for approval.
Apply Now: https://www.gate.com/questionnaire/7159
Token rewards, exclusive Gate merch, and traffic exposure await you!
Details: https://www.gate.com/announcements/article/47889
Fusion contract hacked, $267,000 transferred to Tornado Cash, DeFi security sounds the alarm again
According to the latest news, CertiK Alert detected a serious security vulnerability in the Fusion PlasmaVault contract on January 7. During a withdrawal operation, hackers used the configured “fuse” contract to transfer all funds (approximately $267,000) to EOA address 0x9b1b, then bridged across chains to Ethereum and deposited into Tornado Cash mixer. This incident once again exposes the security risks in DeFi protocols during the contract configuration phase.
Event Details: The Complete Chain from Configuration to Obfuscation
Attack Process Analysis
The core of this attack lies in exploiting the time gap:
The key to this process is the vulnerability in the configuration window. Typically, DeFi contracts have insufficient permission checks during initialization or configuration phases, and hackers leverage this time window to complete fund transfers.
Why choose Tornado Cash
Funds entering Tornado Cash mixers is no coincidence; it reflects the hacker’s clear intent:
This choice indicates that hackers have a fairly deep understanding of the DeFi ecosystem and privacy tools.
Larger Security Trend Signals
This is not an isolated incident. According to the latest monitoring data, DeFi security incidents are occurring frequently:
Both events reflect the same issue: Weak permission control during DeFi contract initialization and configuration phases.
Why do such vulnerabilities persist
Insights for Users and Projects
Reminders for project teams
Recommendations for users
Summary
The severity of the Fusion incident is not only in the $267,000 loss but also in revealing a systemic vulnerability. The hacker’s full chain—from exploiting the configuration window, through cross-chain transfer, to entering the mixer—indicates that attacks targeting DeFi have become a mature routine.
It also serves as a reminder to the entire ecosystem: Audits and monitoring are important but not foolproof. True security requires project teams to consider security thoroughly during design, and users to stay vigilant. While DeFi offers attractive yields, risk management must always come first.