Sonic DEX traces $276,000 exploit and plans compensation portal for affected users

Sonic DEX has published an official report into a security incident that led to the unauthorised extraction of assets from 26 liquidity pools, with estimated losses of about $276,000.

The incident occurred on 15 July 2026 and prompted an investigation by the platform’s engineering and security teams, who examined the technical cause of the exploit, tracked the movement of the stolen assets on-chain, and contacted centralised exchanges and law enforcement agencies.

According to the report, the exploit was caused by a transaction atomicity vulnerability linked to the asynchronous execution model used by Internet Computer canisters. Sonic said the attacker was able to submit a large number of precisely timed asynchronous requests that altered execution ordering during intermediate state transitions.

The platform said the exploit did not involve compromised private keys or administrative access. Instead, it took advantage of an edge case in the protocol’s execution flow, allowing funds to be extracted before the final transaction state had been reconciled.

Sonic said the affected functionality was disabled after the vulnerability was identified, and architectural changes are being implemented to prevent similar attacks.

The forensic investigation traced the stolen assets through multiple intermediary wallets, token swaps and cross-chain transfers before they were converted into Bitcoin and eventually deposited at the HitBTC exchange.

The report states that about $195,000 was consolidated into a primary attacker wallet, while smaller amounts were distributed across three secondary wallets. Investigators said the attacker moved 96,780 ICP through a relay wallet, converted the assets into ckBTC through ICPSwap, liquidated about 30 million BOOM tokens, and later transferred the proceeds into a central aggregation wallet.

Sonic said approximately 3.145 BTC was converted into native Bitcoin through 62 separate burn transactions before being moved through a series of peel-chain wallets and deposited into a HitBTC address.

The company said it had contacted exchanges connected to the movement of funds and provided transaction records and forensic evidence. It said the exchanges had acknowledged receipt of the reports and indicated they would cooperate with law enforcement investigations where legally permitted.

Sonic also said investigators had identified an additional lead involving funding received by the attacker-controlled wallet about a month before the exploit.

The platform said it is continuing to work with authorities, while noting that identifying the individual behind the exchange account would require information held by the exchange and the appropriate legal process.

Alongside the investigation, Sonic announced plans to change the direction of the platform. It intends to phase out its liquidity pool protocol and focus on AI-powered token discovery, market analytics, token aggregation and investing tools.

The company said the redesign has been under development for several months and is intended to improve security, performance and long-term sustainability.

Sonic also announced that it plans to launch a compensation portal next week for affected users. Eligible users will be asked to submit their wallet address, details of affected assets and supporting information for verification.

The company said claims will be reviewed against on-chain records and that it intends to compensate eligible users either fully or partially, depending on the recovery process and available funds. Compensation is expected to be distributed directly to users’ wallets over the coming month.

The report says the current focus is on reimbursing regular community users who were directly affected by the exploit, with further details on eligibility, verification procedures and compensation timelines to be announced before the portal goes live.

Sonic said it would continue pursuing recovery of the stolen assets, cooperating with exchanges and law enforcement, and providing further updates as the investigation progresses.


Dear Reader,

Ledger Life is an independent platform dedicated to covering the Internet Computer (ICP) ecosystem and beyond. We focus on real stories, builder updates, project launches, and the quiet innovations that often get missed.

We’re not backed by sponsors. We rely on readers like you.

If you find value in what we publish—whether it’s deep dives into dApps, explainers on decentralised tech, or just keeping track of what’s moving in Web3—please consider making a donation. It helps us cover costs, stay consistent, and remain truly independent.

Your support goes a long way.

🧠 ICP Principal: ins6i-d53ug-zxmgh-qvum3-r3pvl-ufcvu-bdyon-ovzdy-d26k3-lgq2v-3qe

🧾 ICP Address: f8deb966878f8b83204b251d5d799e0345ea72b8e62e8cf9da8d8830e1b3b05f

Every contribution helps keep the lights on, the stories flowing, and the crypto clutter out.

Thank you for reading, sharing, and being part of this experiment in decentralised media.
—Team Ledger Life

0

Community Discussion

Loading discussion…

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More like this

Menese promotes decentralised multichain asset management for institutions

Menese is promoting a decentralised approach to digital asset management, positioning its platform as an alternative to...

Oisy points to seedless wallet model after $38m Bitcoin...

A Bitcoin theft involving an estimated US$38 million has renewed attention on how hardware wallets generate and...

MULTI/DEX opens Phase II trading competition and releases exchange...

MULTI/DEX has launched Phase II of its trading competition and released its exchange code as open source,...