0xMarkets Suffers Major Liquidity Pool Breach
Bittensor subnet 35’s 0xMarkets suffered an attack that drained its liquidity pools, including team-held positions. The team says attackers compromised GCP deployment environments, introduced a malicious smart contract, and is working with AMLBot to trace and recover funds.
This is a sharp reminder that audited DeFi contracts are only one layer of security; deployment infrastructure and upgrade controls can be equally decisive.
- –The reported GCP compromise turned operational access into direct protocol-level loss.
- –Pausing contracts limited further damage, but could not reverse funds already drained.
- –Blacklisting addresses may help if stolen assets reach centralized exchanges or bridges, but recovery remains uncertain.
- –LPs faced both smart-contract risk and infrastructure/custody risk despite 0xMarkets’ non-custodial design.
- –A credible recovery plan should include a technical postmortem, affected-wallet accounting, and stricter multisig, deployment, and upgrade controls.
DISCOVERED
1d ago
2026-08-26
PUBLISHED
1d ago
2026-08-26
RELEVANCE
AUTHOR
subnetradarcom
