Monday, June 8, 2026
Catatonic Times
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
No Result
View All Result
Catatonic Times
No Result
View All Result

Yuga Labs Just Pulled Off A $500,000 Crypto Heist — Against These Hackers

by Catatonic Times
June 8, 2026
in Crypto Updates
Reading Time: 4 mins read
0 0
A A
0
Home Crypto Updates
Share on FacebookShare on Twitter


Trusted Editorial content material, reviewed by main business specialists and seasoned editors. Advert Disclosure

Yuga Labs, the corporate behind Bored Ape Yacht Membership and CryptoPunks, accomplished a covert whitehat operation on June 8 to rescue 68 blue-chip NFTs — value greater than $500,000 — from an energetic exploit focusing on Flooring Protocol, deploying its personal funds and appearing earlier than extra attackers may drain belongings that included a number of the most precious tokens in NFT historical past.

Yuga Labs CEO Michael Figge (@mfigge) introduced the profitable operation on X, publishing a full stock of the rescued belongings now held within the firm’s custody: 29 Bored Ape Yacht Membership NFTs, 4 Mutant Apes, one Bored Ape Kennel Membership token, two CryptoPunks, one Azuki, two Elementals, 26 Captains, one Moonbird, and two Doodles. “We’ve simply completed a whitehat operation on an exploit found in Flooring Protocol,” Figge wrote, noting that Yuga Labs VP of Blockchain 0xQuit (@0xQuit) led the on-chain restoration effort.

The operation was funded by way of GrailsOTC, Yuga Labs’ over-the-counter buying and selling desk — which Figge stated he “quietly instructed” to entrance the capital and NFTs wanted to tug the at-risk belongings out of the protocol earlier than extra dangerous actors may act on the identical vulnerability. The corporate plans to return all 68 NFTs to their authentic homeowners as soon as a technical repair has been deployed and verified.

How The Crypto Exploit Labored

The mechanics of the assault, defined in a technical thread by 0xQuit on X, reveal a complicated vulnerability embedded in Flooring Protocol’s core accounting logic. A malicious actor turned a mud quantity of WETH — a negligible amount — right into a near-infinite fpToken stability by exploiting an edge case in how the protocol dealt with token possession data. The attacker then used the inflated stability to empty Flooring swimming pools, with a subsequent opportunist scooping up the now-depleted pool tokens and exchanging them for the underlying NFTs.

The deeper vulnerability, per 0xQuit’s publish, got here from packed possession and indexing logic — a technical design selection the place a malicious token ID may make possession verification checks go whereas downstream accounting recorded a special end result totally, creating what he described as “ghost possession.” An unchecked stability replace then prompted an arithmetic underflow, handing the attacker a stability far bigger than legitimately entitled. As soon as that inflated stability was in place, token costs could possibly be pushed close to zero and liquidity extracted from the pool at will.

After reviewing the preliminary assault path, Yuga Labs’ crew recognized a second, broader vulnerability that uncovered extra NFT swimming pools not but touched by the unique attacker. That discovery triggered the emergency whitehat operation — the crew moved to tug all at-risk belongings earlier than one other actor may discover and exploit the identical second path independently.

Ethereum ETH ETHUSD ETHUSD_2026-06-08_17-12-22

ETH’s value data some upside on low timeframes as seen on the day by day chart. Supply: ETHUSD on Tradingview

The Protocol Behind The Incident

Flooring Protocol’s architect, @0xFreeLunch, acknowledged on X that the vulnerability originated in gas-saving bit-level code design — a category of optimization the place builders scale back computational prices by packing a number of values into shared storage slots. Regardless of a number of safety opinions, the flaw went undetected, per his publish. The admission is notable: fuel optimization trade-offs that seem secure in isolation can create exploitable floor space when token IDs fall exterior anticipated ranges.

Flooring Protocol had already been winding down its consumer-facing NFT providers since September 2025 — the platform suggested FPv2 token holders to redeem belongings and exit fractional positions earlier than October of that yr. But its sensible contracts remained reside with person belongings inside, creating precisely the type of legacy publicity that attackers more and more goal in ageing DeFi infrastructure.

0xQuit warned on X that some NFTs stay underneath attacker management and urged all customers to keep away from depositing extra NFTs into Flooring Protocol till a verified repair is deployed. CryptoPunks — two of which have been among the many rescued belongings — presently carry a flooring value of roughly 32.7 ETH, or roughly $54,612 per token, whereas BAYC NFTs sit round 9.16 ETH, per CoinGecko knowledge.

This growth marks a pivotal and strange second for the nascent sector’s method to DeFi safety. A blue-chip NFT firm deploying its personal stability sheet to rescue third-party belongings from an energetic exploit — unprompted, at velocity, and at price — is a type of ecosystem accountability the area not often sees. The query the business will now ask is what number of different ageing protocols nonetheless carry related vulnerabilities of their legacy contracts, ready for the attacker who finds the second path earlier than anybody else does.

Cowl picture from Grok, ETHUSD chart from Tradingview

Editorial Course of for bitcoinist is centered on delivering totally researched, correct, and unbiased content material. We uphold strict sourcing requirements, and every web page undergoes diligent evaluation by our crew of prime expertise specialists and seasoned editors. This course of ensures the integrity, relevance, and worth of our content material for our readers.



Source link

Tags: cryptoHackersHeistLabspulledYuga
Previous Post

Win $500 in Celo’s Onchain Agents Hackathon — Optimize Trading Activity With Carbon DeFi

Related Posts

Bitcoin Surges 5% to K, Settles Near .5K as Trump Says Netanyahu Must Accept Iran Deal
Crypto Updates

Bitcoin Surges 5% to $64K, Settles Near $62.5K as Trump Says Netanyahu Must Accept Iran Deal

June 8, 2026
Crypto Moves Into The Mainstream Of Vietnam’s Digital Economy
Crypto Updates

Crypto Moves Into The Mainstream Of Vietnam’s Digital Economy

June 8, 2026
Here’s Why Bitcoin’s 50% Drop Looks Mild Next to What Several Altcoin Holders Are Sitting On
Crypto Updates

Here’s Why Bitcoin’s 50% Drop Looks Mild Next to What Several Altcoin Holders Are Sitting On

June 7, 2026
Monero Next? Researcher Who Found The Zcash Flaw Targets XMR For Future Audit
Crypto Updates

Monero Next? Researcher Who Found The Zcash Flaw Targets XMR For Future Audit

June 7, 2026
Hut 8 Prices .25B Notes to Build 352MW Texas AI Data Center
Crypto Updates

Hut 8 Prices $4.25B Notes to Build 352MW Texas AI Data Center

June 7, 2026
Zcash Suffers Historic Collapse As Billions Vanish From Market Value
Crypto Updates

Zcash Suffers Historic Collapse As Billions Vanish From Market Value

June 7, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Catatonic Times

Stay ahead in the cryptocurrency world with Catatonic Times. Get real-time updates, expert analyses, and in-depth blockchain news tailored for investors, enthusiasts, and innovators.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

Latest Updates

  • Yuga Labs Just Pulled Off A $500,000 Crypto Heist — Against These Hackers
  • Win $500 in Celo’s Onchain Agents Hackathon — Optimize Trading Activity With Carbon DeFi
  • Why Is Wall Street Already Buying Back In?
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.