T
iTokenly

Munchables hack — March 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 27, 2024
Target typeGaming or metaverse
Loss$62,500,000Price at time of incident
Recovered$62,500,000
MethodInsider actiona developer pre-wrote a fabricated 1,000,000 ETH deposit balance into proxy storage before an implementation upgrade, then withdrew against it
ChainsBlast
Attributed toa developer hired by Munchables, using the aliases NelsonMurua913, Werewolves0493, BrightDragon0719 and Super1114; assessed by ZachXBT to be North KoreanSuspected
OutcomeFunds returned

What happened

Munchables, an NFT game on the Blast layer-2 network, lost 17,413 ETH — about $62.5 million — on 26 March 2024. The contract holding user deposits was an upgradeable proxy whose implementation had been deployed from an unverified address controlled by a developer rather than by the project.

Blockchain developer 0xQuit, quoted by Unchained, described the sequence: while an early implementation was live, a privileged party manually wrote storage slots to credit an address with a large deposited ether balance, then swapped in an implementation that looked legitimate and enforced normal withdrawal checks. The fabricated balance survived the upgrade, and the holder withdrew against it once enough value had accumulated in the contract. 0xQuit said the attack "does require you to be an authorized party and was probably an inside job by a rogue dev."

On-chain investigator ZachXBT linked the exploiting address to a developer Munchables had hired, operating under the aliases NelsonMurua913, Werewolves0493, BrightDragon0719 and Super1114 — likely one person — and assessed the developer to be North Korean on the basis of GitHub commit activity and on-chain evidence. No charges have been brought and the North Korea link rests on researcher analysis rather than a government attribution.

The funds came back within a day and without a ransom. Munchables said the developer voluntarily handed over all relevant private keys, including one holding 73 WETH and the owner key holding the remainder. Blast founder Pacman said the returned assets were consolidated into a multisig controlled by Blast core contributors holding roughly $97 million in total, for redistribution to Munchables and other affected protocols. Munchables said all user funds were safe.

Law enforcement

No arrests, charges or sanctions have been reported.

Sources

  1. UnchainedSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. CryptoSlateSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Munchables hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/munchables
https://itokenly.com/hacks/munchables

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.