Munchables hack — March 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 27, 2024 |
| Target type | Gaming or metaverse |
| Loss | $62,500,000Price at time of incident |
| Recovered | $62,500,000 |
| Method | Insider actiona developer pre-wrote a fabricated 1,000,000 ETH deposit balance into proxy storage before an implementation upgrade, then withdrew against it |
| Chains | Blast |
| Attributed to | a developer hired by Munchables, using the aliases NelsonMurua913, Werewolves0493, BrightDragon0719 and Super1114; assessed by ZachXBT to be North KoreanSuspected |
| Outcome | Funds returned |
What happened
Munchables, an NFT game on the Blast layer-2 network, lost 17,413 ETH — about $62.5 million — on 26 March 2024. The contract holding user deposits was an upgradeable proxy whose implementation had been deployed from an unverified address controlled by a developer rather than by the project.
Blockchain developer 0xQuit, quoted by Unchained, described the sequence: while an early implementation was live, a privileged party manually wrote storage slots to credit an address with a large deposited ether balance, then swapped in an implementation that looked legitimate and enforced normal withdrawal checks. The fabricated balance survived the upgrade, and the holder withdrew against it once enough value had accumulated in the contract. 0xQuit said the attack "does require you to be an authorized party and was probably an inside job by a rogue dev."
On-chain investigator ZachXBT linked the exploiting address to a developer Munchables had hired, operating under the aliases NelsonMurua913, Werewolves0493, BrightDragon0719 and Super1114 — likely one person — and assessed the developer to be North Korean on the basis of GitHub commit activity and on-chain evidence. No charges have been brought and the North Korea link rests on researcher analysis rather than a government attribution.
The funds came back within a day and without a ransom. Munchables said the developer voluntarily handed over all relevant private keys, including one holding 73 WETH and the owner key holding the remainder. Blast founder Pacman said the returned assets were consolidated into a multisig controlled by Blast core contributors holding roughly $97 million in total, for redistribution to Munchables and other affected protocols. Munchables said all user funds were safe.
Law enforcement
No arrests, charges or sanctions have been reported.
Sources
- UnchainedSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CryptoSlateSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Munchables hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/munchableshttps://itokenly.com/hacks/munchablesPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.