CheckoutPool Hack
What happened
Fun.xyz's legacy CheckoutPool settlement contract was exploited in the March 16-17, 2026 UTC window. The listed date is March 16, while BlockSec timestamps the exploit transaction to March 17 UTC. Approximately 85,730 USDC was transferred on Polygon through the vulnerable bridge path.
The legacy CheckoutPool exposed bridge() without enforcing onlyOperator and failed to bind caller-supplied bridgeParams.target and bridgeParams.callData to the checkout's intended recipient. Because the legacy pool still held operator privileges in CheckoutPaymaster, a crafted bridge call reached execute() and transferred settlement funds to an attacker-controlled smart account.
How it happened
The attacker created an ERC-4337 smart account, deposited into the legacy and new CheckoutPool contracts, and called legacy bridge() with bridgeParams.target set to CheckoutPaymaster and callData encoding activateAndCall() around a malicious UserOperation. The path reached the new pool's execute(), which transferred 85,730 USDC to the attacker's smart account.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.