SUPERFORTUNE AI Hack

Reported loss $15.2M
Ethereum
Authorization Compromise

What happened

On May 27, 2026, SUPERFORTUNE AI reported an unauthorized transfer of roughly $15.18M face value in GUA tokens.

reporting estimated approximately $5.66M in realized proceeds; these figures describe different scopes.

Technical root cause

The signing and transfer workflow did not reliably verify the final recipient after authorization was compromised, allowing a lookalike address to receive the token allocation. Public reporting attributes the compromise to leaked signing material, but does not establish the complete intrusion chain.

How it happened

The attacker redirected an intended multisig airdrop to a lookalike address. SUPERFORTUNE AI attributed the event to a leaked signing private key and forged or replayed authorization, while the exact intrusion path remains dependent on project reporting.

Protocol details

Classification Access Control
Protocol Type Token

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.