Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Launchpad
Be early to the next big token project
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Web3 Game Munchables Loses $62.5 Million to Exploit: ZachXBT
Hongji Feng
Last updated:
March 27, 2024 02:26 EDT | 1 min read
Munchables confirmed the exploit through a post on social media, stating the loss occurred on March 26. “Munchables has been compromised,” said Munchables. “We are tracking movements and attempting to stop the the transactions. We will update as soon as we know more.”
Investigation Suggests Potential Link to Munchables Insider
According to ZachXBT, the crypto “detective,” the exploiter extracted nearly 17,414 ETH with a total value of $62.5 million as indicated by Blastscan.
ZachXBT then made some more digging and discovered that the exploit could be initiated by a Munchables employee, since they have been recruited as four developers.
“Four different devs hired by the Munchables team and linked to the exploiter are likely all the same person as they recommended each other for the job,” said ZachXBT.
The suspect also “regularly transferred payments to the same two exchange deposit addresses” and “funded each others wallets.” ZachXBT included the alleged exploiter’s GitHub usernames in the post, ing the community.
Exploit Rooted in Upgrade Manipulation
Solidity developer 0xQuit revealed in a post that the exploit was premeditated, highlighting that a developer had modified the Lock contract to a new version just before the game’s release. This contract is designed to secure tokens for a set period.
“The Munchables exploit has been planned since deploy,” said 0xQuit, stating that the platform is a “dangerously upgradeable proxy.” The exploiter was able to abuse the upgrade and implementation to assign themselves 1 million ETH so they could withdraw the deposit.
“If you never knew about the original implementation, the contract would look just fine,” explained 0xQuit. “Even if the dev had transferred ownership back to the team, the damage was done,” the author added, discouraging upgradeability.
Responding to the devastating incident, the team has announced to provide all relevant private keys to aid in the retri of user funds. This includes the key associated with $62,535,441.24 USD, another holding 73 WETH, and the owner key that secures the remaining funds.
Follow Us on Google News