Vulcan Forged hack — December 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Gaming or metaverse |
| Loss | $140,000,000Price at time of incident |
| Method | Private key compromisePlatform servers compromised, wallet-provider credentials abused to export user private keys |
| Chains | Ethereum, Polygon |
| Outcome | Users reimbursed |
What happened
Vulcan Forged, a blockchain gaming and NFT studio behind the PYR token, ran a semi-custodial wallet service called MyForge built on infrastructure from the wallet provider Venly. On 12 December 2021 an attacker who had compromised Vulcan Forged's own servers obtained the platform's Venly credentials, intercepted user PINs and used them to export private keys for user wallets. Venly said the export calls all originated from Vulcan Forged IP addresses and so appeared legitimate to its systems, that no Venly servers were compromised, and that no other Venly clients or end users were affected — claims that rest on Venly's own account and were not independently verified. Vulcan Forged's chief executive, Jamie Thomson, initially said Venly's services had been compromised and later retracted that.
The wallets were drained in the early hours of 13 December 2021, around 00:30 CET. Venly said at least 96 Vulcan Forged wallets were affected, the same count Vulcan Forged gave. About 4.5 million PYR were taken. Contemporary reporting valued the haul at roughly $140 million, a figure resting on the pre-incident price; PYR then fell about a third, to around $21, as the stolen tokens were sold, so the amount realised by the attacker was almost certainly lower than the headline number — an inference from the reported price move rather than a figure any publisher measured.
Vulcan Forged accepted responsibility and refunded affected users from its treasury within about a day, paying in PYR and LAVA. The company said it would remove the semi-custodial wallet arrangement from the whole Vulcan ecosystem and move users to self-custody. The attacker was not identified publicly and the stolen tokens were not recovered.
Sources
- VenlyPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
Official post-mortem: https://www.venly.io/blog/venly-informs-of-vulcan-forged-hack-with-at-least-96-vulcan-forged-wallets-affected
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Vulcan Forged hack — December 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/vulcan-forgedhttps://itokenly.com/hacks/vulcan-forgedPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.