SUPERFORTUNE AI Hack
What happened
On May 27, 2026, SUPERFORTUNE AI reported an unauthorized transfer of roughly $15.18M face value in GUA tokens.
reporting estimated approximately $5.66M in realized proceeds; these figures describe different scopes.
The signing and transfer workflow did not reliably verify the final recipient after authorization was compromised, allowing a lookalike address to receive the token allocation. Public reporting attributes the compromise to leaked signing material, but does not establish the complete intrusion chain.
How it happened
The attacker redirected an intended multisig airdrop to a lookalike address. SUPERFORTUNE AI attributed the event to a leaked signing private key and forged or replayed authorization, while the exact intrusion path remains dependent on project reporting.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.