Legacy Polygon Royalties Contract Exploit Drains $261K Through Reward Logic Flaw

TheNewsCryptoPublicado em 2026-06-24Última atualização em 2026-06-24

Resumo

A hacker exploited a legacy Polygon royalties contract, stealing approximately $261,200 in cryptocurrency. Security firm TenArmorAlert identified the attack on June 23. The exploit was made possible by a flaw in the contract's reward calculation logic within the Royal1155LD.beforeLdaTransfer() function. By executing several zero-value transactions, the attacker manipulated reward accounting and token ownership data, artificially inflating balances to enable excessive withdrawals. The attacker also utilized a flash loan to amplify the exploit's profit after repayment. This incident highlights ongoing security risks associated with older, inactive smart contracts that still hold funds, following similar recent exploits. Developers are urged to audit, update, or decommission such legacy deployments to prevent future attacks. The Polygon blockchain's core infrastructure was not compromised.

A hacker used a legacy royalties contract on the Polygon platform and made away with about $261,200 worth of cryptocurrency in recent times. The security firm TenArmorAlert identified the unusual transaction on June 23 and tracked down the exploit transaction.

The blockchain shows that the hacker carried out the attack using the Polygon block 89,018,051 transaction. According to TenArmorAlert, the hacker managed to withdraw roughly $263,800 despite the relatively low initial amount of money. The attack was on the legacy royalties program and not the fundamental structure of the Polygon blockchain.

Miscalculation in Reward Calculation Allowed for Overdraws

According to TenArmorAlert, the attack was possible due to issues in the reward calculation mechanism and reward accounting. Security company CertiK found out about an issue with the Royal1155LD.beforeLdaTransfer() function in the exploited contract.

Researchers state that the attacker made several zero-value transactions, manipulating reward calculation and ownership numbers. This vulnerability allowed the attacker to make the token balance higher under certain conditions.

The Defimon Alerts also provided other research by DecurityHQ. In this case, experts concluded that royalty miscalculations led to the exploit. This way, false ownership numbers were allowing for excessive reward claiming. In addition, the attacker used a flash loan to exploit this contract. After repaying the borrowed amount, the attacker got the rest of the money as a profit.

Still Vulnerable to Security Threats

The latest attack has come in light of other similar attacks on older versions of decentralized finance projects as well as dormant smart contract deployments. Attackers have recently carried out an exploitation of some old contracts of Huma Finance and have stolen roughly $101,400.

Researchers have been cautioning developers regarding the possible dangers of having old versions of smart contracts with available finances. The team should audit, update, deactivate, or completely remove the old deployment in order to mitigate the danger of any potential attacks. Polygon developers have confirmed that attackers have not been able to threaten the security of the main blockchain network.

Highlighted Crypto News:

SecondFi Exploit Exposes Wallet Keys, Putting More Than $20M in Cardano Assets at Risk

TagsBlockchainCryptocurrencyHackHack AttackPolygonPolygon NetworkRewards

Perguntas relacionadas

QWhat was the primary vulnerability that allowed the hacker to drain funds from the legacy Polygon royalties contract?

AThe primary vulnerability was a flaw in the reward calculation mechanism and reward accounting within the contract. Specifically, a miscalculation in the `Royal1155LD.beforeLdaTransfer()` function allowed the attacker to manipulate reward calculations and ownership numbers, enabling them to inflate token balances and withdraw excessive funds.

QHow much cryptocurrency did the hacker manage to steal in the exploit, according to the article?

AThe hacker stole approximately $261,200 worth of cryptocurrency. A specific transaction tracked by TenArmorAlert shows the hacker withdrew roughly $263,800 from the contract.

QWhat technique did the attacker use to exploit the contract, aside from manipulating the reward logic?

AIn addition to manipulating the reward logic, the attacker used a flash loan to exploit the contract. They borrowed funds to execute the attack and, after repaying the loan, kept the remaining amount as profit.

QAccording to the article, what action should developers take to mitigate the risk of similar attacks on older smart contracts?

ADevelopers should audit, update, deactivate, or completely remove old deployments of smart contracts that still hold available finances. This is necessary to mitigate the danger of potential attacks targeting legacy code with known or newly discovered vulnerabilities.

QDid the exploit compromise the core security of the Polygon blockchain itself?

ANo, the exploit did not compromise the core security of the Polygon blockchain. The attack targeted a specific, legacy royalties program contract, not the fundamental structure of the Polygon network. Polygon developers confirmed that the main blockchain network's security was not threatened.

Leituras Relacionadas

Everyone Thinks Cryptocurrency is Dead, But He Says It's About to Explode

Title: A Bullish Case Amidst Doubt: Bitcoin's Path for Ordinary Investors While many declare crypto dead, Scott Melker argues the opposite. In a wide-ranging interview, he reflects on the industry's evolution into a more institutionalized landscape in 2026. Dismissing the myth of trading success, Melker advocates for "boring" investment as the key to financial freedom for the average person. His core advice is straightforward: buy Bitcoin, consistently dollar-cost average, and hold. He warns against trying to time the volatile market, calling it a dangerous path where most lose out. Melker shares his journey from a DJ and trader to a media entrepreneur, highlighting the importance of building a durable brand based on reputation rather than hype. He acknowledges the structural shifts in the market, noting that many tokens fail to accrue value to holders, while assets with real institutional adoption, like Bitcoin, Ethereum, and Solana, will thrive. The lessons from the 2022 bear market are clear: avoid unrealistic yield traps and focus on hard assets. For investors, he recommends an 80% Bitcoin, 10% Ethereum, 10% Solana portfolio, using strategies to generate cash flow to buy more Bitcoin. Melker's ultimate goal is promoting Bitcoin to the mainstream, viewing it as the most critical financial asset for escaping the inflationary "rat race." His philosophy for 2026 and beyond is simple: "Bitcoin and chill." He urges investors to stay the course, emphasizing that the current market, with its institutional adoption and ETFs, represents the industry's best era yet.

marsbitHá 3m

Everyone Thinks Cryptocurrency is Dead, But He Says It's About to Explode

marsbitHá 3m

Why Are Crypto VCs Focusing on Stablecoin Infrastructure?

Crypto VC Focuses on Stablecoin Payment Infrastructure Despite an overall cooling crypto VC market in Q1 2026, investment in stablecoin payment infrastructure is gaining momentum. Capital is concentrating on mature projects with existing users, transaction volume, and clearer revenue models over purely speculative token-based ventures. Stablecoins are evolving from trading tools into backend infrastructure for efficient, 24/7 cross-border payments (e.g., B2B, remittances, payroll). Startups are building along the entire payment stack—connecting stablecoins to bank accounts, cards, forex liquidity, and local compliance systems. Recent large funding rounds for companies like Rain (cards), OpenFX (cross-border), and RedotPay highlight this trend. VC interest stems from several factors: solving real inefficiencies in traditional cross-border settlement, established fee-based revenue models (transaction fees, forex spreads), stablecoins becoming an invisible backend tool for end-users, clearer US regulatory frameworks attracting traditional finance, and acquisition exits to companies like Stripe and Mastercard. However, challenges remain. High on-chain stablecoin volume doesn't equal real retail payment volume; funding is concentrated in a few top performers; services risk commoditization; global expansion requires navigating local banking and regulations per market; and large traditional payment firms are both potential clients and future competitors. Future investment may focus on cross-border B2B payments, bank-stablecoin connectivity, stablecoin-linked cards, multi-chain/asset payment orchestration platforms, and infrastructure for AI Agent payments. Ultimately, VCs are betting not on a single stablecoin's dominance, but on the critical infrastructure needed to integrate programmable, global settlement assets into the traditional financial system.

marsbitHá 5m

Why Are Crypto VCs Focusing on Stablecoin Infrastructure?

marsbitHá 5m

Billions in USDT Flee Korea. Police Powerless in the Fight Against Money Laundering

South Korea is facing a severe and rapidly escalating challenge with crypto-based money laundering. Police data shows cases surged 152-fold in the first half of 2026 compared to all of 2025, with laundering now constituting 79.4% of all detected crypto-related crimes. The primary method is the "Hwanchigi" scheme, which uses cryptocurrency transfers to move illicit funds overseas, bypassing the regulated banking system. Tether (USDT) is the preferred vehicle for converting proceeds from drug trafficking, illegal gambling, and phishing into dollars before moving them to offshore exchanges. Despite enhanced monitoring and enforcement efforts, a stark gap exists between detection and prosecution. While authorities tracked and blocked millions in illegal assets in high-profile cases, arrests have lagged dramatically. In the first half of 2026, only 18 arrests were made despite over 1,200 detected cases. Customs seized approximately $4.92 billion in illegal foreign exchange operations, with over 90% of crypto-related crimes for prosecution flowing through unlicensed channels. The situation highlights a systemic disconnect: blockchain analytics can track transactions nearly in real-time, but the judicial process moves slowly. This asymmetry raises questions about whether detection statistics alone are a meaningful measure of effectiveness in combating money laundering, as the low cost and high speed of these schemes allow criminal networks to scale faster than law enforcement can respond.

cryptonews.ruHá 19m

Billions in USDT Flee Korea. Police Powerless in the Fight Against Money Laundering

cryptonews.ruHá 19m

Trading

Spot
活动图片