• Economy
  • Investing
  • Editor’s Pick
  • Stock
Evil Shark Trades
Editor's Pick

Web3 Game Munchables Loses $62.5 Million to Exploit: ZachXBT

by March 27, 2024
by March 27, 2024

The web3 gaming platform Munchables experienced a significant security breach, losing $62.5 million in Ethereum due to an exploit on the Blast network.

Munchables confirmed the exploit through a post on social media, stating the loss occurred on March 26. “Munchables has been compromised,” said Munchables. “We are tracking movements and attempting to stop the the transactions. We will update as soon as we know more.”

Munchables has been compromised. We are tracking movements and attempting to stop the the transactions. We will update as soon as we know more.

— Munchables (@_munchables_) March 26, 2024

Investigation Suggests Potential Link to Munchables Insider


According to ZachXBT, the crypto “detective,” the exploiter extracted nearly 17,414 ETH with a total value of $62.5 million as indicated by Blastscan.

ZachXBT then made some more digging and discovered that the exploit could be initiated by a Munchables employee, since they have been recruited as four developers.

Four different devs hired by the Munchables team and linked to the exploiter are likely all the same person as they:

>recommended each other for the job
>regularly transferred payments to the same two exchange deposit addresses >funded each others wallets

Github Username… https://t.co/Q0scxp6AxK pic.twitter.com/Pjjo4uKXPE

— ZachXBT (@zachxbt) March 27, 2024

“Four different devs hired by the Munchables team and linked to the exploiter are likely all the same person as they recommended each other for the job,” said ZachXBT.

The suspect also “regularly transferred payments to the same two exchange deposit addresses” and “funded each others wallets.” ZachXBT included the alleged exploiter’s GitHub usernames in the post, alerting the community.

Exploit Rooted in Upgrade Manipulation


Solidity developer 0xQuit revealed in a post that the exploit was premeditated, highlighting that a developer had modified the Lock contract to a new version just before the game’s release. This contract is designed to secure tokens for a set period.

“The Munchables exploit has been planned since deploy,” said 0xQuit, stating that the platform is a “dangerously upgradeable proxy.” The exploiter was able to abuse the upgrade and implementation to assign themselves 1 million ETH so they could withdraw the deposit.

3/ Shortly thereafter, it was upgraded to the new implementation.

Here, there were appropriate checks to ensure you couldn’t withdraw more than you deposited. But before upgrading, the attacker was able to assign himself a deposited balance of 1,000,000 Ether pic.twitter.com/LrzhYiRWkb

— quit.q00t.eth (,) (@0xQuit) March 26, 2024

“If you never knew about the original implementation, the contract would look just fine,” explained 0xQuit. “Even if the dev had transferred ownership back to the team, the damage was done,” the author added, discouraging upgradeability.

Responding to the devastating incident, the team has announced to provide all relevant private keys to aid in the retrieval of user funds. This includes the key associated with $62,535,441.24 USD, another holding 73 WETH, and the owner key that secures the remaining funds.

The post Web3 Game Munchables Loses $62.5 Million to Exploit: ZachXBT appeared first on Cryptonews.

0 comment
0
FacebookTwitterPinterestEmail

previous post
Gaming Firm Illuvium Raises $12M Funding Led by King River Capital, Arrington and Animoca
next post
HSBC Launches Gold Token Service for Retail Investors in Hong Kong

You may also like

Josh Fraser, Co-Founder of Origin Protocol, on Liquid...

Hong Kong Legislator Raises Concern Over Crypto Licensing...

Bitcoin Price Prediction: $150K Forecast and ETF Market...

Veteran Analyst Peter Brandt Predicts Bitcoin Price to...

Robinhood Implements Buying Restrictions on GameStop As Roaring...

Over $3 Billion Worth of ETH Withdrawn from...

Matter Labs Withdraws ‘ZK’ Trademark Application After Industry...

Rwanda to Roll Out CBDC By 2026 After...

El Salvador’s President Nayib Bukele Sworn in for...

FTX Estate Sells Off Remaining Anthropic Holdings Amid...

Enter Your Information Below To Receive Free Trading Ideas, Latest News And Articles.






    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Recent Posts

    • Trump’s spending bill heads to Senate where Republicans plan strategic adjustments to key provisions
    • Digital Social Security cards coming this summer
    • 5 terrifying flashpoints that could ignite global war
    • Tesla stock sinks as Musk and Trump ridicule each other
    • Trump ally stands firm against ‘big, beautiful bill’ despite pressure: ‘It’ll completely backfire’

    Categories

    • Economy (6,180)
    • Editor's Pick (3,862)
    • Investing (2,826)
    • Stock (1,325)
    Email Whitelisting About Us Terms & Conditions Privacy Policy Contact Us

    Disclaimer: Evilsharktrades.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Copyright © 2024 EvilSharkTrades.com


    Back To Top
    Evil Shark Trades
    • Economy
    • Investing
    • Editor’s Pick
    • Stock