SubQuery Network Hack

REPORTED LOSS $134K
Low Acces Control Exploit base

What happened

On April 12, 2026, five transactions exploited SubQuery Network's Settings contract on Base and drained 382,433,441 SQT, valued at approximately $134,000 at the time. The incident affected pooled staking balances, 272 staker and delegator wallets, deployment boosters, and a small treasury balance.

Technical Root Cause

The Settings contract's setContractAddress function lacked an onlyOwner modifier, so any caller could update addresses for critical protocol roles including StakingManager and RewardsDistributor.

Case & protocol details

Classification Protocol Logic / Access Control
Implementation language Solidity
Official Website www.subquery.network
Protocol Twitter/X @subquerynetwork

Market Context at Time of Hack

Token Price at Hack $0.00050108
Market Cap at Hack $1.9M
Reported loss / token market cap 7.06%
Token Categories
Cosmos Ecosystem Enterprise Solutions DApp Ethereum Ecosystem Analytics DCG Portfolio Polygon Ecosystem Fantom Ecosystem

How it happened

The attacker used permissionless Settings functions to change the registered StakingManager and RewardsDistributor addresses to attacker-controlled helpers, then used the poisoned dependencies to withdraw pooled and individual staked SQT. The team restored the original addresses and deployed a fix.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.