T
iTokenly

Foom.Cash hack — February 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 26, 2026
Target typeOther
Loss$2,260,000Published estimates range $1,600,000 to $2,260,000Price at time of incident
Recovered$1,840,000
MethodSignature verification flawThe Groth16 verifier embedded in the contracts had its verifying-key parameters gamma and delta set to the same elliptic-curve point, because a snarkjs Phase 2 trusted-setup step was skipped at deployment and the values were left at their defaults. CertiK described the condition as delta2 equal to gamma2, which collapses the pairing check separating public inputs from the private witness and allows a valid-looking proof to be computed for any nullifier hash from public data alone, enabling repeated withdrawals without a matching deposit.
ChainsEthereum, Base
OutcomePartially recovered

What happened

Foom.Cash, a zero-knowledge privacy pool marketed as a successor to Tornado Cash, was drained on 26 February 2026 on Ethereum and Base. Deposits in its pools could be withdrawn by anyone able to present a proof the contract would accept, and a deployment error meant forged proofs were accepted.

The fault lay in the Groth16 verifier embedded in the contracts. Foom said a command-line step was missed during the Phase 2 trusted setup, leaving the verifying-key parameters unrandomised so that gamma and delta ended up as the same elliptic-curve point. CertiK, quoted by Cryptopolitan and The Crypto Times, described the condition as delta2 equal to gamma2. QuillAudits reached the same root cause independently, gamma equal to delta, and explained that the equality collapses the pairing check separating public inputs from the private witness, so an attacker can compute every proof parameter from public data alone and withdraw repeatedly with incrementally modified nullifier hashes without having deposited. BlockSec, whose Phalcon system flagged the transactions, called it an imitation attack exploiting the same root cause as the earlier Veil Cash exploit.

The totals are contested and FOOM is thinly traded, so dollar marks are unreliable. Cryptopolitan reported 24,283,773,519,600 FOOM tokens moved out of the pools, worth about $2.26 million, and attributed roughly $1.83 million of that on Ethereum to a white-hat rescue rather than to the attacker, with about $427,000 on Base taken by the malicious actor. QuillAudits puts the amount drained substantially lower, at about $1.616 million, being $1.3 million on Ethereum and $316,000 on Base. Cointelegraph reported on 2 March that about $1.84 million, 81 percent, had been secured or recovered by the pseudonymous researcher Duha and the security firm Decurity, leaving around $420,000 unrecovered, with Foom paying Duha a $320,000 bounty and Decurity a $100,000 fee. Cointelegraph places Duha on Base and Decurity on Ethereum, which does not sit easily with the per-chain figures, and no reconciled accounting of the loss has been published.

Sources

  1. CryptopolitanSecondary · retrieved 2026-08-01
  2. The Crypto TimesSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. QuillAuditsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Foom.Cash hack — February 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/foom-cash
https://itokenly.com/hacks/foom-cash

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.