Enjin Hack

Reported loss $162K
Ethereum
Unprotected Initialization and Ownership Takeover

What happened

An attacker drained ENJ-backed Crypto Items from approximately 52 Ethereum wallets on 25 August 2026, then melted the items to redeem their ENJ reserves. Published reporting places the value at roughly $142,000.

Technical root cause

An unprotected adapter initialization path enabled unauthorized manager control over Crypto Items.

How it happened

The attacker used an adapter path that allowed manager control to be initialized without the expected approval. That control was used to transfer value-backed ERC-1155 items from affected wallets and melt them for ENJ.

Protocol details

Classification Access Control
Protocol Type NFTfi
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.