De-fi
Analysts Believe Munchables’ $63M Exploit Was Internally Engineered – Crypto News
Experts believe the Blast-based game’s $63 million hack may have been devised by a North Korean employee.
Munchables, a prominent web3 game and farm on the Blast Layer 2 network, has suffered a $63 million hack, igniting debate about whether the Blast team should roll back the malicious transaction.
The incident took place on March 26, with Munchables tweeting that it is actively tracking the flow of funds stolen in the exploit. Two-thirds of Munchables’ total value locked (TVL) was stolen as a result of the incident, with the protocol’s TVL sliding from $96.2 million to $34 million, according to DeFi Llama.
ZachXBT, a popular web3 analyst and sleuth, identified the attacker’s wallet on-chain. The address currently holds 17,412.65 Ether.
Inside job?
0xQuit, a Solidity auditor, said the protocol’s lock contract was engineered to lay the groundwork for the exploit prior to Munchables’ deployment.
They said the contract was originally unverified and written to allow the attacker to assign themselves a deposited balance of up to 1 million ETH, before being upgraded to a new implementation that concealed the vulnerability.
“If you never knew about the original implementation, the contract would look just fine” 0xQuit tweeted. “[The] scammer used manual manipulation of storage slots to assign himself an enormous Ether balance before changing the contract implementation to one that appears legit. Then he simply withdrew that balance once TVL was juicy enough.”
ZachXBT speculated that the attack may have been engineered by a North Korean developer hired by the Munchables team.
Onlookers debate network rollback
The incident has given rise to fervent discussions regarding how Blast should next proceed, with Blast possessing the ability to reverse the malicious transaction and exercising control over its bridge to the Ethereum mainnet — which cannot be bypassed by third-party bridges.
0xQuit tweeted that third-party Blast bridges appear to have been disabled to protect their operators against potential losses. “Makes sense given the uncertainty,” 0xQuit tweeted. “If Blast rolls back… these bridges are out of pocket on everything they paid out to bridgers, and bridgers would double their money.”
DCF God, a popular crypto trader, said rolling back the exploit would not comprise a major departure from Blast’s existing ethos, with the network already exhibiting a centralized architecture.
“Don’t think it’s too crazy for Blast to freeze the underlying ETH from the Munchables exploit,” DCF God said. “It’s not like other L2s because they manage the underlying deposits already.”
However, many onlookers warned that reversing transactions would set a poor precedent for the project moving forward.
“Technically, the Blast team could recover the $62m lost in the Munchables exploit since they control the bridge contract that holds the bridged ETH/stETH,” tweeted 0xCygaar, a contributor to Frame. “I don’t think any rollup has done something like this on mainnet yet but the bridge contracts are upgradeable… It wouldn’t set a good precedent for future exploits/issues, but it is possible.“
However, many web3 users said they would prefer for Blast to roll back the chain to return assets to victims, despite the risks and centralization concerns associated with such a move.
“Blast can get $62m in stolen ETH back because it controls the bridge to mainnet,” tweeted Beanie, an NFT investor. “There’s literally no reason for Blast not to act for the benefit of its users.”
Brentsketit, a crypto commentator and investor, said they would feel “safer” engaging with a network that responds to exploits in a centralized manner. “As anti-crypto as that sounds, but it seems crypto is nowhere close to its root anymore,” they tweeted.
However, CL207 of eGirl Capital, a Blast investor, said they heard that multiple solutions are currently being discussed, and that a roll back may not be needed.
Exploit pours cold water over Blast
The incident serves as a dampener following Blast’s impressive but controversial mainnet launch four weeks ago.
Blast deployed as the third-largest L2 with a TVL of more than $2 billion owing to accepting deposits to a one-way bridging contract since announcing its launch plans in November.
However, the launch campaign, which offered users yields via third-party protocols in addition to Blast points, was criticized for demanding trust from users despite failing to publish any code or audits alongside leveraging incentive structures borrowed from multi-level-marketing schemes.
Blast is now the third-ranked L2 with a network TVL of $2.7 billion, according to L2beat.
-
Cryptocurrency1 week agoVanEck’s Solana ETF nears launch after SEC 8-A filing – Details – Crypto News
-
Cryptocurrency1 week agoVanEck’s Solana ETF nears launch after SEC 8-A filing – Details – Crypto News
-
De-fi1 week agoZEC Jumps as Winklevoss‑Backed Cypherpunk Reveals $100M Zcash Treasury – Crypto News
-
Business7 days ago
December Fed Meeting 2025: Rate Cut or Hold? Key levels to Watch – Crypto News
-
Metaverse7 days agoClaude Desktop is your new best friend for an organized PC – Crypto News
-
De-fi1 week agoKraken’s xStocks Hit $10B in Total Trading Volume – Crypto News
-
others7 days ago
December Fed Meeting 2025: Rate Cut or Hold? Key levels to Watch – Crypto News
-
Metaverse7 days agoClaude Desktop is your new best friend for an organized PC – Crypto News
-
Cryptocurrency1 week agoBitcoin faces quantum risk: why SegWit wallets may offer limited protection – Crypto News
-
Metaverse1 week agoYour deep research tool may save you time, but can it save you embarrassment? – Crypto News
-
Technology5 days agoPerplexity faces harsh crowd verdict at major San Francisco AI conference: ‘Most likely to flop’ – Crypto News
-
Technology5 days ago
Japan’s ¥17 Trillion Stimulus Plan: A Turning Point for Global Liquidity Shifts – Crypto News
-
De-fi1 week agoSKY Surges 14% as Savings TVL Passes $4 Billion – Crypto News
-
Cryptocurrency1 week agoUAE makes Bitcoin wallets a crime risk in global tech crackdown – Crypto News
-
De-fi1 week agoEthereum Sees First Sustained Validator Exit Since Proof-of-Stake Shift – Crypto News
-
Cryptocurrency1 week agoXRP’s Big Moment? Why Nov. 13 Could Be the Day Ripple Investors Have Waited For – Crypto News
-
De-fi1 week agoXPL Rallies After Plasma Reveals Collaboration with Daylight Energy – Crypto News
-
Cryptocurrency1 week agoBitcoin (BTC) battles macro headwinds despite improved ETF inflows – Crypto News
-
Cryptocurrency1 week agoAI-driven phishing scams and hidden crypto exploits shake Web3 security – Crypto News
-
Blockchain1 week agoWhy the Future of Blockchain Payments Could Stay Narrow – Crypto News
-
Cryptocurrency5 days agoCrypto market’s weekly winners and losers – TEL, STRK, ICP, CC – Crypto News
-
Blockchain5 days agoBitcoin Indicator Sounds Buy Alarm For The First Time Since March — Return To $110K Soon? – Crypto News
-
Cryptocurrency5 days agoCrypto update: Bitcoin ETFs see $300M inflow as investors ‘buy the dip’ – Crypto News
-
Cryptocurrency4 days agoTLC Coin Price Prediction 2026, 2030, &2040: Trillioner Forecast » InvestingCube – Crypto News
-
De-fi1 week agoTrump Tokens Outperform After US President Teases ‘Tariff Dividends’ – Crypto News
-
Metaverse1 week agoFoxconn reports strong Q3 profit driven by AI server boom, teases OpenAI announcement – Crypto News
-
others1 week ago
Hyperliquid Halts Deposits and Withdrawals Amid POPCAT Liquidation Saga – Crypto News
-
Business1 week ago
Hyperliquid Halts Deposits and Withdrawals Amid POPCAT Liquidation Saga – Crypto News
-
De-fi1 week agoFlare TVL Nears Record High as Firelight Teases XRP Liquid Staking – Crypto News
-
De-fi6 days agoBitcoin Drops to $94,000 Following Second-Largest Daily ETF Outflows – Crypto News
-
De-fi6 days agoBitcoin Drops to $94,000 Following Second-Largest Daily ETF Outflows – Crypto News
-
Technology5 days agoAI chatbots like ChatGPT and Gemini may be ‘bullshitting’ to keep you happy, new study finds – Crypto News
-
Blockchain5 days agoA16z’s Sees Arcade Tokens As Key To Crypto Evolution – Crypto News
-
Blockchain4 days agoBlackRock XRP ETF Speculation Hit New Highs As XRPC Performance Shocks Markets – Crypto News
-
Blockchain1 week agoBitcoin Path To $1 Million Clears With OG Sellers Fading: Weisberger – Crypto News
-
Technology1 week ago
Breaking: USDC Issuer Circle Explores Native Token for Arc Network – Crypto News
-
De-fi1 week agoXRP Surges as First US Spot ETF Debuts on Nasdaq – Crypto News
-
Business1 week ago
Ethereum Price Sheds 10% but Lands on the $3,150 Accumulation Base — Is a Buy-the-Dip Bounce Ahead? – Crypto News
-
Blockchain1 week agoZcash Revival Sparks Debate on Bringing Privacy Back to Bitcoin – Crypto News
-
Blockchain4 days agoAnt International and UBS Team on Blockchain-Based Deposits – Crypto News
-
Business1 week ago
Arthur Hayes Buys UNI as CryptoQuant CEO Says Supply Shock ‘Inevitable’ for Uniswap – Crypto News
-
Business1 week ago
Cardano News: Wirex Partners EMURGO To Launch First Ever ADA Card – Crypto News
-
Cryptocurrency1 week agoUniswap finally turns the fee switch – Crypto News
-
Business1 week ago
U.S. Government Shutdown Set to End as House Panel Approves Senate Funding Deal – Crypto News
-
Cryptocurrency1 week agoMatthew McConaughey, Michael Caine Team Up With ElevenLabs to Recreate Their Voices Using AI – Crypto News
-
Cryptocurrency1 week agoMajor Ethereum Upgrade Scheduled for December – Crypto News
-
Business1 week ago
Death Cross Triggers Sell Signals for Cardano Price— Will ADA Retest $0.50? – Crypto News
-
Cryptocurrency1 week agoCanary XRP ETF gets green light for Nasdaq launch tomorrow – Crypto News
-
Blockchain1 week agoEthereum Slips After Rebound, Struggling to Keep Momentum Above $3,500 – Crypto News
-
De-fi1 week agoLarge POPCAT Trades Result in $5 Million Loss for Hyperliquid Vault – Crypto News
