CheckoutPool Hack

Reported loss $86K
Polygon
Unprotected bridge()

What happened

Fun.xyz's legacy CheckoutPool settlement contract was exploited in the March 16-17, 2026 UTC window. The listed date is March 16, while BlockSec timestamps the exploit transaction to March 17 UTC. Approximately 85,730 USDC was transferred on Polygon through the vulnerable bridge path.

Technical root cause

The legacy CheckoutPool exposed bridge() without enforcing onlyOperator and failed to bind caller-supplied bridgeParams.target and bridgeParams.callData to the checkout's intended recipient. Because the legacy pool still held operator privileges in CheckoutPaymaster, a crafted bridge call reached execute() and transferred settlement funds to an attacker-controlled smart account.

How it happened

The attacker created an ERC-4337 smart account, deposited into the legacy and new CheckoutPool contracts, and called legacy bridge() with bridgeParams.target set to CheckoutPaymaster and callData encoding activateAndCall() around a malicious UserOperation. The path reached the new pool's execute(), which transferred 85,730 USDC to the attacker's smart account.

Protocol details

Classification Access Control / Calldata Binding
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.