Mure Hack

Reported loss $12K
Ethereum
Signature Verification

What happened

On May 23, 2026, MureDistribution's QUEST distribution proxy on Ethereum was exploited for approximately $11,700. The attacker pulled about 4.85 million QUEST from addresses that had approved the proxy.

Technical root cause

The distribution proxy trusted a user-supplied signer source during signature validation, allowing an attacker-controlled contract to satisfy the signer check and authorize transfers from existing token allowances.

How it happened

The attacker supplied a contract of their own as the signer source, passed the proxy's signature-check path, and used the resulting authorization to transfer QUEST from approved addresses before swapping the proceeds.

Protocol details

Classification Input Validation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.