Munchables Hack

REPORTED LOSS $62.5M
High Proxy Upgrade Hijack Blast

What happened

Munchables, a Blast-based game, was drained of about $62.5 million in ETH on March 26, 2024 after a privileged developer exploited a backdoor embedded in the protocol's upgradeable contracts. The attacker later provided the relevant private keys, enabling recovery of the stolen assets.

Technical Root Cause

A developer retained unilateral control over upgradeable contract logic and used it to seed attacker-controlled storage before replacing the visible implementation. Because proxy calls use delegatecall, the manipulated state persisted after the implementation was changed, allowing attacker addresses to pass the registration and unlock checks.

Case & protocol details

Classification Access Control
Protocol Type Farm
Implementation language Solidity
Official Website www.munchables.app/
Protocol Twitter/X @_munchables_

How it happened

The attacker used pre-planted state in proxy-backed contracts to satisfy the staking contract's authorization and time-lock checks. They then called unlock from a registered attacker address and transferred roughly 17,414 ETH from the contract.

Funds Recovery

100%

Recovered

$62.5M

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.