Share this article

DeFi Protocol Qubit Finance Exploited for $80M

The attack is the seventh-largest DeFi exploit by the amount of funds stolen, data shows.

Updated May 11, 2023, 4:41 p.m. Published Jan 28, 2022, 7:15 a.m.
(Azamat E/Unsplash, modified by CoinDesk)
(Azamat E/Unsplash, modified by CoinDesk)

Binance Smart Chain-based Qubit Finance was exploited for over $80 million by attackers on Friday morning, developers confirmed in a post.

  • “The hacker minted unlimited xETH to borrow on BSC. The team is currently working with security and network partners on next steps,” developers said in a tweet.
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
  • Addresses connected to the attack show 206,809 Binance coins were drained from Qubit’s QBridge protocol. The assets are worth over $80 million at current prices, security firm PeckShield confirmed in a tweet.
  • Decentralized finance (DeFi) projects like Qubit Finance rely on smart contracts instead of third parties to offer users financial services such as trading, lending and borrowing.
  • Qubit allows users to supply their crypto holdings to the protocol and borrow loans against this collateral for a fixed fee. QBridge is a cross-chain feature that enables users to collateralize their assets on other networks without moving assets from one chain to another.
  • PeckShield, which audited Qubit’s smart contracts, said the QBridge was hacked to mint a “huge amount of xETH collateral” that was then used to drain the entire amount of BNB held on QBridge.
  • In an incident report, security firm CertiK said the attacker used a deposit function in the QBridge contract and illicitly minted 77,162 qXETH, an asset that represents ether bridged via Qubit. Attackers tricked the protocol to show that they had deposited funds without making an actual deposit.
  • These steps were repeated several times, and the attacker then converted all the assets to BNB, CertiK said in a tweet.
  • The exploit is the seventh-largest attack on a DeFi protocol by the amount of funds stolen, as per data from analytics tool DeFi Yield.
  • Qubit’s QBT is down 25% in the past 24 hours, as per data from CoinGecko. Much of the fall occurred after this morning’s incident was made public.
  • Qubit developers continue to monitor the situation at the time of writing, as per a tweet.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

KindlyMD faces Nasdaq delisting risk after failing to meet minimum share price levels

NAKA (TradingView)

The health-care and bitcoin treasury firm has six months to lift its share price above $1 for 10 consecutive days.

What to know:

  • The Nasdaq exchange told KindlyMD (NAKA) that it faces being delisted after its share price dropped below $1 for 30 consecutive business days.
  • The health-care company that is building a bitcoin treasury has until June 8 to regain compliance, which requires the stock to close at or above $1 for at least 10 consecutive business days.
  • The shares first fell below $1 in late October, and closed Monday at $0.38.