SubQuery Network Hack
What happened
On April 12, 2026, five transactions exploited SubQuery Network's Settings contract on Base and drained 382,433,441 SQT, valued at approximately $134,000 at the time. The incident affected pooled staking balances, 272 staker and delegator wallets, deployment boosters, and a small treasury balance.
The Settings contract's setContractAddress function lacked an onlyOwner modifier, so any caller could update addresses for critical protocol roles including StakingManager and RewardsDistributor.
Case & protocol details
How it happened
The attacker used permissionless Settings functions to change the registered StakingManager and RewardsDistributor addresses to attacker-controlled helpers, then used the poisoned dependencies to withdraw pooled and individual staked SQT. The team restored the original addresses and deployed a fix.
Evidence & learning
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.