Munchables Hack
What happened
Munchables, a Blast-based game, was drained of about $62.5 million in ETH on March 26, 2024 after a privileged developer exploited a backdoor embedded in the protocol's upgradeable contracts. The attacker later provided the relevant private keys, enabling recovery of the stolen assets.
A developer retained unilateral control over upgradeable contract logic and used it to seed attacker-controlled storage before replacing the visible implementation. Because proxy calls use delegatecall, the manipulated state persisted after the implementation was changed, allowing attacker addresses to pass the registration and unlock checks.
Case & protocol details
How it happened
The attacker used pre-planted state in proxy-backed contracts to satisfy the staking contract's authorization and time-lock checks. They then called unlock from a registered attacker address and transferred roughly 17,414 ETH from the contract.
Funds Recovery
Recovered
$62.5M
Net Loss
$0
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.