T
iTokenly

SubQuery Network hack — April 2026

Verified — 5 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedApril 13, 2026
Target typeInfrastructure provider
Loss$134,000Price at time of incident
MethodAccess control flawSubQuery's Settings contract let anyone overwrite the addresses of the network's other contracts, so the attacker made its helper the StakingManager and RewardsDistributor and withdrew the Staking contract's SQT
ChainsBase
OutcomeUsers reimbursed

What happened

SubQuery Network, a decentralised data-indexing network whose SQT token is staked on Base, lost 382,433,441 SQT, about $134,000 at the time by its own count, from its Staking contract on 12 April 2026, in transactions between 04:35 and 06:51 UTC. SubQuery published a full disclosure the next day: 272 staker and delegator wallets were directly affected, and it said no staker or delegator would bear any loss, crediting affected wallets on-chain on 14 and 15 April.

The cause was a missing owner check on the Settings contract, which records the addresses of the network's other contracts. The attacker pointed the StakingManager and RewardsDistributor entries at its own helper contract, which the Staking contract then trusted: acting as the rewards distributor it created an unbond request for the Staking contract's whole liquid SQT balance, and acting as the staking manager it withdrew it at once, before restoring the original settings.

This registry read the largest of the transactions, at 05:04:45 UTC, in which 218,070,478 SQT reached the attacker's address. SQT was thinly traded, with a market value of about $2.27m and some $102,000 of daily volume according to Defimon Alerts, so the dollar figure is SubQuery's conversion at the price of the time rather than an amount the attacker could have realised.

Sources

  1. SubQuery incident reportPrimary · retrieved 2026-10-06
  2. Defi Nerd on XSecondary · retrieved 2026-10-06
  3. Defimon Alerts on TelegramSecondary · retrieved 2026-10-06
  4. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  5. Base transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Official post-mortem: https://subquery.ghost.io/subquery-network-security-incident-report/

Changes to this entry

  • Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SubQuery Network hack — April 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/subquery-network-april-2026
https://itokenly.com/hacks/subquery-network-april-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.