• bitcoinBitcoin (BTC) $ 59,834.00
  • ethereumEthereum (ETH) $ 1,578.30
  • tetherTether (USDT) $ 0.998354
  • bnbBNB (BNB) $ 552.04
  • usd-coinUSDC (USDC) $ 0.999606
  • xrpXRP (XRP) $ 1.05
  • solanaSolana (SOL) $ 72.28
  • tronTRON (TRX) $ 0.321855
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • hyperliquidHyperliquid (HYPE) $ 62.39
  • dogecoinDogecoin (DOGE) $ 0.072834
  • usdsUSDS (USDS) $ 0.999421
  • rainRain (RAIN) $ 0.015553
  • leo-tokenLEO Token (LEO) $ 9.42
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 379.64
  • stellarStellar (XLM) $ 0.172715
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 309.95
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • canton-networkCanton (CC) $ 0.147949
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • whitebitWhiteBIT Coin (WBT) $ 47.89
  • chainlinkChainlink (LINK) $ 7.30
  • cardanoCardano (ADA) $ 0.144276
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.998873
  • daiDai (DAI) $ 0.999581
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998027
  • labLAB (LAB) $ 14.25
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.60
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 194.21
  • litecoinLitecoin (LTC) $ 42.91
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.071405
  • global-dollarGlobal Dollar (USDG) $ 0.999496
  • avalanche-2Avalanche (AVAX) $ 6.59
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.687222
  • paypal-usdPayPal USD (PYUSD) $ 0.999806
  • crypto-com-chainCronos (CRO) $ 0.054052
  • tether-goldTether Gold (XAUT) $ 4,051.42
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • nearNEAR Protocol (NEAR) $ 1.85
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • bittensorBittensor (TAO) $ 206.46
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.058871
  • pax-goldPAX Gold (PAXG) $ 4,055.68
  • uniswapUniswap (UNI) $ 2.95
  • aster-2Aster (ASTER) $ 0.625927
  • okbOKB (OKB) $ 78.27
  • ripple-usdRipple USD (RLUSD) $ 0.999959
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.310764
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • worldcoin-wldWorldcoin (WLD) $ 0.433287
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • aaveAave (AAVE) $ 94.04
  • falcon-financeFalcon USD (USDF) $ 0.995003
  • mantleMantle (MNT) $ 0.426830
  • polkadotPolkadot (DOT) $ 0.820540
  • usddUSDD (USDD) $ 0.998343
  • pi-networkPi Network (PI) $ 0.122038
  • bfusdBFUSD (BFUSD) $ 0.997822
  • internet-computerInternet Computer (ICP) $ 2.17
  • skySky (SKY) $ 0.049910
  • morphoMorpho (MORPHO) $ 1.77
  • bitget-tokenBitget Token (BGB) $ 1.63
  • ethereum-classicEthereum Classic (ETC) $ 7.03
  • dexeDeXe (DEXE) $ 21.77
  • united-stablesUnited Stables (U) $ 0.999506
  • pepePepe (PEPE) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.03
  • quant-networkQuant (QNT) $ 65.42
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • kucoin-sharesKuCoin (KCS) $ 6.78
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • memecoreMemeCore (M) $ 0.648488
  • stable-2​​Stable (STABLE) $ 0.035463
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdgoUSDGO (USDGO) $ 0.999969
  • cosmosCosmos Hub (ATOM) $ 1.58
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.54
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • algorandAlgorand (ALGO) $ 0.089004
  • velvetVelvet (VELVET) $ 1.85
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • kaspaKaspa (KAS) $ 0.028009
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.13
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.071829
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • audieraAudiera (BEAT) $ 2.65
  • justJUST (JST) $ 0.088578
  • usdtbUSDtb (USDTB) $ 0.999530
  • ethenaEthena (ENA) $ 0.078406
  • nexoNEXO (NEXO) $ 0.724614
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.210803
  • gatechain-tokenGate (GT) $ 6.54
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.692819
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • beldexBeldex (BDX) $ 0.085250
  • adi-tokenADI (ADI) $ 5.04
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • venice-tokenVenice Token (VVV) $ 13.01
  • ghoGHO (GHO) $ 0.997727
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • pump-funPump.fun (PUMP) $ 0.001424
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • filecoinFilecoin (FIL) $ 0.722660
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • flare-networksFlare (FLR) $ 0.006596
  • yldsYLDS (YLDS) $ 0.999516
  • xdce-crowd-saleXDC Network (XDC) $ 0.027770
  • clbtcclBTC (CLBTC) $ 76,920.00
  • usual-usdUsual USD (USD0) $ 0.998478
  • midnight-3Midnight (NIGHT) $ 0.031451
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.35
  • usxUSX (USX) $ 0.999476
  • true-usdTrueUSD (TUSD) $ 0.997548
  • hash-2Provenance Blockchain (HASH) $ 0.008971
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • arbitrumArbitrum (ARB) $ 0.075747
  • aptosAptos (APT) $ 0.578388
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • a7a5A7A5 (A7A5) $ 0.012179
  • tbtctBTC (TBTC) $ 70,942.00
  • injective-protocolInjective (INJ) $ 4.62
  • aerodrome-financeAerodrome Finance (AERO) $ 0.473673
  • lighterLighter (LIT) $ 1.74
  • euro-coinEURC (EURC) $ 1.14
  • dashDash (DASH) $ 32.70
  • jito-governance-tokenJito (JTO) $ 0.842574
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.70
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • hastra-primePRIME (PRIME) $ 1.05
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.179863
  • official-trumpOfficial Trump (TRUMP) $ 1.66
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • vechainVeChain (VET) $ 0.004539
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006113
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • celestiaCelestia (TIA) $ 0.382518
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.535917
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996822
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000062
  • ethgas-2ETHGas (GWEI) $ 0.160856
  • sei-networkSei (SEI) $ 0.049993
  • the9bitThe9bit (9BIT) $ 0.042627
  • sun-tokenSun Token (SUN) $ 0.016727
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • ether-fiEther.fi (ETHFI) $ 0.342966
  • blockstackStacks (STX) $ 0.168543
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 129.73
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • grassGrass (GRASS) $ 0.504578
  • spx6900SPX6900 (SPX) $ 0.328115
  • curve-dao-tokenCurve DAO (CRV) $ 0.190460
  • apxusdapxUSD (APXUSD) $ 0.743282
  • gnosisGnosis (GNO) $ 107.86
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • pyth-networkPyth Network (PYTH) $ 0.035869
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • kite-2Kite (KITE) $ 0.119588
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bitcoin-svBitcoin SV (BSV) $ 12.71
  • plasmaPlasma (XPL) $ 0.095675
  • olympusOlympus (OHM) $ 15.95
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • fraxLegacy Frax Dollar (FRAX) $ 0.990212
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • tezosTezos (XTZ) $ 0.212792
  • megausdMegaUSD (USDM) $ 1.00
  • unibaseUnibase (UB) $ 0.090429
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • zebec-networkZebec Network (ZBCN) $ 0.002298

Legacy Polygon Royalties Contract Exploit Drains $261K Through Reward Logic Flaw

0 0


  • A hacker took advantage of a legacy contract for Polygon royalties and drained $261,200 as a result of the vulnerability in the reward calculation.
  • The security experts attributed the problem to flawed reward calculations leading to inflated ownership balances and exaggerated rewards.

A hacker used a legacy royalties contract on the Polygon platform and made away with about $261,200 worth of cryptocurrency in recent times. The security firm TenArmorAlert identified the unusual transaction on June 23 and tracked down the exploit transaction.

The blockchain shows that the hacker carried out the attack using the Polygon block 89,018,051 transaction. According to TenArmorAlert, the hacker managed to withdraw roughly $263,800 despite the relatively low initial amount of money. The attack was on the legacy royalties program and not the fundamental structure of the Polygon blockchain.

🚨TenArmor Security Alert🚨

Our system has detected a suspicious attack involving an old contract #Royalties on #Polygon, resulting in an approximately loss of $261.2K.

Attack transaction: https://t.co/C2TTD661uK

With TenArmor’s TenMonitor, you get early detection and… pic.twitter.com/nlh0fhBan4

— TenArmorAlert (@TenArmorAlert) June 24, 2026

Miscalculation in Reward Calculation Allowed for Overdraws

According to TenArmorAlert, the attack was possible due to issues in the reward calculation mechanism and reward accounting. Security company CertiK found out about an issue with the Royal1155LD.beforeLdaTransfer() function in the exploited contract.

#CertiKInsight 🚨

We have seen a $263K exploit on the Royalties contract at 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7 on Polygon.

Through 100 zero-value transfers, the attacker exploited flawed settlement logic to stack reward records and claim 100X reward.

Stay Vigilant! pic.twitter.com/Jjt2yNwZUc

— CertiK Alert (@CertiKAlert) June 24, 2026

Researchers state that the attacker made several zero-value transactions, manipulating reward calculation and ownership numbers. This vulnerability allowed the attacker to make the token balance higher under certain conditions.

The Defimon Alerts also provided other research by DecurityHQ. In this case, experts concluded that royalty miscalculations led to the exploit. This way, false ownership numbers were allowing for excessive reward claiming. In addition, the attacker used a flash loan to exploit this contract. After repaying the borrowed amount, the attacker got the rest of the money as a profit.

🚨 @join_royal – Loss $261K (2026-06-23)

Token: $USDC
Network: Polygon

Type: Logic Error (pro-rata royalty accounting)

Royal’s Royalties contract pays out claims as deposit × (LDA tier balance / tier supply). The attacker flash-loaned $USDC, acquired an outsized tier-42 LDA…

— Defimon Alerts (@DefimonAlerts) June 24, 2026

Still Vulnerable to Security Threats

The latest attack has come in light of other similar attacks on older versions of decentralized finance projects as well as dormant smart contract deployments. Attackers have recently carried out an exploitation of some old contracts of Huma Finance and have stolen roughly $101,400.

Researchers have been cautioning developers regarding the possible dangers of having old versions of smart contracts with available finances. The team should audit, update, deactivate, or completely remove the old deployment in order to mitigate the danger of any potential attacks. Polygon developers have confirmed that attackers have not been able to threaten the security of the main blockchain network.





Source link

Leave A Reply

Your email address will not be published.