Refreshed 5h ago· updates every 6h

Munchables (2024) — Crypto Hack

Fully Recovered
Mar 26, 2024·
Blast
Amount Stolen
$62.5M
~17,400 ETH
Recovered
$62.5M
100% of stolen funds

A rogue developer socially engineered his way into Munchables and embedded a self-destruct lockContract function that let him drain ~17,400 ETH (~$62.5M) from the Blast-based game.

Summary

A rogue developer socially engineered his way into Munchables and embedded a self-destruct lockContract function that let him drain ~17,400 ETH (~$62.5M) from the Blast-based game.

How It Was Compromised — DeFi via Social Engineering / Insider Key Compromise

DeFiSocial Engineering / Insider Key Compromise

Munchables, a Blast-based NFT game, was drained of approximately 17,400 ETH (~$62.5M) on March 26, 2024. The attacker was a contracted developer who had concealed his identity and embedded a hidden lockContract function in the smart contract that granted him the ability to unlock and withdraw all deposited funds. The developer had previously been hired under a false identity and used multiple aliases to gain the team's trust. Within hours of the exploit, the developer voluntarily returned all stolen funds after the on-chain identity was uncovered.

Fund Flow & Laundering Analysis

No laundering occurred — the attacker returned the full amount within hours after on-chain sleuths and the Munchables team identified the developer's real identity and wallet. Funds were returned to a Munchables-controlled multisig. The incident is one of the rare cases of full recovery without law enforcement intervention.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.