Munchables (2024) — Crypto Hack
Fully RecoveredA rogue developer socially engineered his way into Munchables and embedded a self-destruct lockContract function that let him drain ~17,400 ETH (~$62.5M) from the Blast-based game.
Summary
A rogue developer socially engineered his way into Munchables and embedded a self-destruct lockContract function that let him drain ~17,400 ETH (~$62.5M) from the Blast-based game.
How It Was Compromised — DeFi via Social Engineering / Insider Key Compromise
Munchables, a Blast-based NFT game, was drained of approximately 17,400 ETH (~$62.5M) on March 26, 2024. The attacker was a contracted developer who had concealed his identity and embedded a hidden lockContract function in the smart contract that granted him the ability to unlock and withdraw all deposited funds. The developer had previously been hired under a false identity and used multiple aliases to gain the team's trust. Within hours of the exploit, the developer voluntarily returned all stolen funds after the on-chain identity was uncovered.
Fund Flow & Laundering Analysis
No laundering occurred — the attacker returned the full amount within hours after on-chain sleuths and the Munchables team identified the developer's real identity and wallet. Funds were returned to a Munchables-controlled multisig. The incident is one of the rare cases of full recovery without law enforcement intervention.