I'm glad to see quick action by the ALEX team to resolve the situation for users, but want to be very clear: it is not a Stacks limitation or vulnerability that caused this exploit.
Having spoken to multiple experienced, independent Stacks developers, the exploit was likely caused by a lack of verification in the ALEX smart contracts as well as the use of a single contract instead of segregated pools as other apps in the ecosystem use. This is why other DeFi apps in the Stacks ecosystem were not exploited despite offering similar functionality.
Again, I'm pleased to see how quickly ALEX is committing to resolving this for their users and taking lessons from this to help all builders build more secure apps, but Stacks users can remain confident in the security and design of the L1.
On June 6, 2025, ALEX Protocol was exploited via a flaw in the self-listing verification logic (an on-chain limitation on Stacks). As a result, the attacker drained several asset pools, with the breakdown of lost assets as follows:
STX: 8,403,867.57 STX → $ 5,691,255.93
sBTC: 21.85 sBTC → $ 2,244,751.87
USDC/USDT: 149,850 USDC/USDT → $ 149,850.00
WBTC/BTC: 2.80 WBTC → $ 287,369.33
Total USD Value Lost: $ 8,373,227.13
Compensation Plan
Full Reimbursement in USDC
Using the ALEX Lab Foundation treasury, we will cover 100 % of each affected user’s loss, paid in USDC. To calculate each reimbursement, we will use the average of on-chain exchange rates taken between 10:00 UTC and 14:00 UTC on June 6, 2025.
Claim Process & Timeline
Notification (by June 8, 2025, 23:59 UTC): All affected wallet addresses will receive a private notification (on-chain) containing a claim form.
Submission Deadline (June 10, 2025, 23:59 UTC): Complete the claim form and confirm your receiving wallet address.
Distribution (within 7 business days after claim): Once your submission is verified, USDC will be sent to your confirmed wallet.
Missing Notice or Questions
If you do not receive a claim notification by June 8, 2025, 23:59 UTC, or if you have any questions about your reimbursement, please contact support@alexlab.co immediately.
We are fully committed to restoring every affected user’s funds (totaling $ 8,373,227.13) as quickly as possible.