← Radar

Incident case file

Sign in to watch

ApeBond — migrateToVotingEscrow Duplicate Pool ID Inflates Lock and Drains ABOND

Incident date June 3, 2026

1 views

ClosedBNB ChainSmart Contract / FlashloanCluster: APEBOND-ESCROW-2026-06

Estimated loss

$3.4K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: 0xE3C6346b6F282029312d2CAf4677EF39BeaBBF99 (confirmed by @audit_911 and @clarahacks June 4 2026) | Seed tx hash: 0x52e42613c6e51b85e4f4eed3fe21a7765752ba4d02e70e8b3e0670d8d30201c6 (mined June 3 2026) | No privileged role needed — attack is fully permissionless on-chain

Funds moved to: ~5.72 WBNB profit (~$3,421) retained by attacker after repaying Moolah flashloan and selling ABOND into the public ABOND/WBNB AlgebraPool. Transaction flow fully on-chain and permissionless per @clarahacks June 4 2026.
ApeYieldVault contract: 0xCFb6B8B220e877C7D9803bf53DA08d78C7F7A535 | VotingEscrow contract: 0xDF1dD618f3B564765e3ffc9F229637942ef601B2 | ABOND token: 0x34294AfABCbaFfc616ac6614F6d2e17260b78BEd | WBNB: 0xbb4CdB9CBd36B01bD1cBaEBF2De08d9173bC095c | Moolah (flashloan): 0x8F73b65B4caAf64FBA2aF91cC5D4a2A1318E5D8C | ABOND/WBNB AlgebraPool: 0x44aA475eD44ddA30F4fB81a0eEC7C44aed01c7c0 | Core bug per @clarahacks: migrateToVotingEscrow adds user.stakedTokens for every _pids entry without checking IDs are un

Timeline: June 3, 2026 — Seed transaction 0x52e42613...0201c6 mined. Attacker EOA 0xE3C6346b...BBF99 begins the exploit with no privileged access required. June 3, 2026 — Attacker uses a public helper contract to call ApeYieldVault.migrateToVotingEscrow with duplicate pool IDs (pool ID 0 passed seventeen times). The bug in the function inflates the lock amount from ~1.71 quadrillion ABOND to ~29.08 quadrillion ABOND (lock tokenId 1157). The helper then unlocks and claims that inflated lock, sells ABOND in the public ABOND/WBNB AlgebraPool, repays the Moolah flashloan principal, and retains ~5.72 WBNB (~$3,421) as profit. June 4, 2026 — @audit_911 publishes exploit details including attacker address and tx. @clarahacks (Real-time DeFiHacks Intelligence, automated by @d23e_AG) relays full technical analysis including the PoC code showing the core bug and concrete numbers. SlowMist Hacked records incident. No post-mortem published by ApeBond team.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)