Rekt's Reader-Commissioned Fiction: A White Hat's Fall and a $100 Million DeFi Revenge Heist
This piece is a work of short fiction, not a report on an actual breach. It was written at the suggestion of a reader, Peter Kacherginsky of the Blockthreat newsletter, who publicly asked whether Rekt would attempt a technical short story grounded in patterns from real-world incidents. The outlet took up the challenge; it notes it remains open to reader ideas via direct message to its X account.
Setup

The story is told in the first person by an anonymous narrator who describes once working as a white-hat blockchain security researcher — someone who searched for vulnerabilities in order to help protocols, not exploit them. Eight months before the events recounted, the narrator says they found a serious flaw in the cross-chain bridge of a protocol called NewDawn: its validation relied on a multi-signature wallet whose signature threshold was set dangerously low. Following what they describe as standard responsible-disclosure practice, they privately reported the issue along with a working proof of concept and offered to help fix it.
According to the narrator, NewDawn went silent for two weeks, then quietly shipped a protocol upgrade that incorporated the reported fixes without any credit or compensation. When the researcher went public about what had happened, NewDawn's communications team framed them as an attention-seeker, and sentiment on Crypto Twitter turned against them overnight. The narrator presents this betrayal as the turning point that pushed them from defender to attacker.
The exploit, as described in the story
NewDawn had recently rolled out a new proof-of-stake consensus system and an optimistic-rollup layer-2. In the narrator's account, the rollup's fraud-proof mechanism held up fine, but the protocol's price oracle did not: it leaned on a single, manipulatable price feed — a shortcut attributed to a rushed launch.
The plan unfolds in stages. First, the narrator deploys dozens of wallets over time, each slowly building a history of ordinary-looking deposits and trades. Next comes a phase of probing transactions across NewDawn's connected lending markets, yield aggregators and synthetic-asset platforms. The final stage combines a large flash loan with a rapid sequence of large trades on illiquid pairs, pushing the manipulated oracle price out of line; a follow-up transaction then borrows against the resulting, artificially inflated collateral. By the narrator's telling, this nets roughly $100 million in crypto — elsewhere in the story described as staked ETH — drained from NewDawn's lending pools, leaving devalued collateral behind.
Aftermath, in the narrative

The story describes the sudden liquidity shortfall setting off a wave of liquidations across connected lending platforms, decentralized exchanges and yield farms. The narrator recounts laundering the proceeds by converting them into privacy-focused tokens, routing through decentralized exchanges, splitting the funds across numerous wallets, and ultimately funneling everything through Tornado Cash forks and layer-2 bridges. NewDawn's team is depicted scrambling — too late — to pause contracts and freeze whatever assets remained.
An encrypted message later reaches the narrator from an ally, described in the story as a well-known hardware-wallet developer recognized for an uncompromising stance on privacy. The message warns that the exploit has drawn attention and that "they're coming for you." The story closes with the narrator moving the stolen funds into a series of hardware wallets, framing the whole episode as both payback against NewDawn and a broader statement about who really holds power in decentralized systems.
Get new scam files the moment we publish them — usually 2–3 emails a week.