Saturday, June 13, 2026
Catatonic Times
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
No Result
View All Result
Catatonic Times
No Result
View All Result

White Hats Rescue $500K in NFTs After Flooring Protocol Exploit White Hats Rescue $500K in NFTs After Flooring Protocol Exploit

by Catatonic Times
June 13, 2026
in NFT
Reading Time: 4 mins read
0 0
A A
0
Home NFT
Share on FacebookShare on Twitter


Yuga Labs-linked white hats rescued 68 NFTs price over $500,000 from an exploit on Flooring Protocol on June 8, 2026, after a flaw within the protocol’s accounting mechanism allowed an attacker to inflate fpToken balances, drain liquidity swimming pools, and alternate tokens for NFTs locked within the contract.

The flaw was not restricted to a single remoted pool. It resided throughout the contract mannequin that converts locked NFTs into fungible tokens, leaving each FloorProtocol V2 and BitmapPunks affected.

What Occurred

The exploit focused the mechanism that permits NFTs locked inside Flooring Protocol to be represented by fungible tokens. In keeping with 0xQuit, VP of Blockchain at Yuga Labs, the attacker used a really small quantity of WETH to generate a near-infinite fpToken steadiness, thereby draining liquidity from Flooring swimming pools.

After a number of swimming pools had been drained, one other handle continued to make the most of the token value being pushed down to close zero to purchase low cost tokens, redeem them for the underlying NFTs, and promote them. The evaluation workforce later found a further associated exploitation path that would have an effect on different swimming pools, together with these containing higher-value NFTs.

FreeLunchCapital, the architect behind the FloorProtocol V2 and BitmapPunks contracts, acknowledged that BitmapPunks was additionally affected as a result of it used the same contract construction. Each used a mannequin the place fungible tokens are pegged 1:1 with NFTs locked within the contract, permitting customers to transform backwards and forwards between tokens and NFTs.

A Flooring exploit immediately turned a mud quantity of WETH right into a near-infinite fpToken steadiness, permitting the attacker to empty Flooring swimming pools.

This led to a followup opportunist scooping up tokens from the now depleted swimming pools and exchanging them for underlying NFTs.

1/🧵

— Stop (@0xQuit) June 8, 2026

In keeping with 0xQuit, the high-value swimming pools had not been attacked primarily resulting from a scarcity of liquidity on Uniswap. As soon as the white hat workforce recognized that the exploitation methodology could possibly be utilized to different susceptible swimming pools, they determined to execute the rescue instantly to mitigate the danger of one other attacker front-running them.

White Hat Response

Michael Figge, CEO of Yuga Labs, acknowledged that the workforce accomplished a white-hat operation on Flooring Protocol. The belongings secured into custody embrace 29 Bored Apes, 4 Mutant Apes, 1 Bored Ape Kennel Membership, 2 CryptoPunks, 1 Azuki, 2 Elementals, 26 Captains, 1 Moonbird, and a couple of Doodles, bringing the entire variety of rescued NFTs to 68.

On this marketing campaign, 0xQuit straight recovered these NFTs. Coffeedev found the danger that would unfold to different Flooring collections corresponding to BAYC and CryptoPunks, whereas GrailsOTC supplied the upfront funds and NFTs required for the rescue.

0xQuit acknowledged that the rescue contract utilized the identical set of flaws defensively to maneuver the at-risk NFTs out of Flooring swimming pools earlier than different attackers may exploit them. The rescued NFTs are valued at over $500,000 and are presently being held to work with related events to return them to their rightful house owners.

How The Exploit Labored

In keeping with 0xQuit, the exploit stemmed from how Flooring Protocol data NFT possession after the NFTs are locked and represented by fpTokens. The exploit mechanism occurred within the following sequence:

Creating an entry level: The attacker used a purposefully generated token ID to make the contract affirm possession as if it had been legitimate.Skewing the accounting: This token ID prompted the possession verify and inner bookkeeping to file mismatched information, making a state of “ghost possession.”Inflating the steadiness: Because the attacker continued to switch or unwrap/burn tokens, subtractions that weren’t correctly checked underflowed, wrapping the fpToken steadiness right into a near-infinite quantity.Draining worth from swimming pools: With the inflated steadiness, the attacker may drive the pool value down to close zero, drain liquidity, and alternate tokens for the underlying NFTs.

FreeLunchCapital additionally acknowledged that the flaw was positioned throughout the bit-level code optimized to scale back fuel charges, which had slipped by way of a number of rounds of safety critiques.

What Stays Unresolved

The incident continues to be not thought-about absolutely resolved. A number of NFTs stay within the arms of the exploiters, whereas the 68 rescued NFTs are presently in custody in preparation for return to their rightful house owners. 0xQuit additionally warned customers to not deposit extra NFTs into Flooring Protocol, as newly deposited belongings may turn into susceptible instantly.

Yuga Labs acknowledged it’s going to coordinate with protocol builders, with the potential want for contract relaunches, token reassurances, or different measures to make sure the return course of doesn’t create extra dangers. On the operational aspect, FreeLunchCapital mentioned they’re working to regain management from the mum or dad group of the administration workforce, whereas coordinating with safety groups and exchanges to hint extracted funds and belongings.

Broader Context

The Flooring Protocol incident additionally highlights the dangers of techniques that convert NFTs into fungible liquidity. When NFTs are locked in a contract and represented by tokens, customers will not be solely uncovered to market dangers but in addition rely upon the protocol’s accounting logic, possession, redemption processes, and liquidity design.

This threat is especially notable as a result of the rescue checklist contains main collections like BAYC and CryptoPunks. If these belongings had been to be redeemed and offered by attackers, the affect may prolong past Flooring Protocol, particularly for fractionalization tasks using comparable contract buildings.



Source link

Tags: 500KexploitFlooringHatsNFTsprotocolRescueWhite
Previous Post

XRP climbs above $1.15 as derivatives activity improves despite market fear

Next Post

Why A Rally To $10 Could Happen Despite Disappointment

Related Posts

Edvard Munch’s chocolate factory series shines a light on the public artist he wanted to be – The Art Newspaper
NFT

Edvard Munch’s chocolate factory series shines a light on the public artist he wanted to be – The Art Newspaper

June 12, 2026
Solana Exchange Raydium Hit With .34 Million Exploit as DeFi Attacks Grow
NFT

Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow

June 11, 2026
Yuga Labs Recovers 68 NFTs Via White-Hat Operation on Flooring Protocol
NFT

Yuga Labs Recovers 68 NFTs Via White-Hat Operation on Flooring Protocol

June 11, 2026
Influential art world figure Joe Hage moves from the shadows to take top billing – The Art Newspaper
NFT

Influential art world figure Joe Hage moves from the shadows to take top billing – The Art Newspaper

June 11, 2026
Bitcoin’s Worst Week Since FTX Crash Signals More Pain Ahead
NFT

Bitcoin’s Worst Week Since FTX Crash Signals More Pain Ahead

June 10, 2026
National Galleries of Scotland announces £56m funding boost for V&A East Storehouse-like gallery in Edinburgh – The Art Newspaper
NFT

National Galleries of Scotland announces £56m funding boost for V&A East Storehouse-like gallery in Edinburgh – The Art Newspaper

June 10, 2026
Next Post
Why A Rally To  Could Happen Despite Disappointment

Why A Rally To $10 Could Happen Despite Disappointment

Kalshi Taps Sportradar for Official League Data and Integrity Tools in Prediction Markets

Kalshi Taps Sportradar for Official League Data and Integrity Tools in Prediction Markets

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Catatonic Times

Stay ahead in the cryptocurrency world with Catatonic Times. Get real-time updates, expert analyses, and in-depth blockchain news tailored for investors, enthusiasts, and innovators.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

Latest Updates

  • Anthropic Disables Fable 5 and Mythos 5 Worldwide After US National Security Order
  • Standard Chartered Says Bitcoin Bottomed Near $59,000, Targets $100,000
  • Web3 in 2026, By the Numbers
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.