Incident case file
Sign in to watchApeBond — migrateToVotingEscrow Duplicate Pool ID Inflates Lock and Drains ABOND
4 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
3 beatsJune 3, 2026 — Seed transaction 0x52e42613...0201c6 mined. Attacker EOA 0xE3C6346b...BBF99 begins the exploit with no privileged access required.
June 3, 2026 — Attacker uses a public helper contract to call ApeYieldVault.migrateToVotingEscrow with duplicate pool IDs (pool ID 0 passed seventeen times). The bug in the function inflates the lock amount from ~1.71 quadrillion ABOND to ~29.08 quadrillion ABOND (lock tokenId 1157). The helper then unlocks and claims that inflated lock, sells ABOND in the public ABOND/WBNB AlgebraPool, repays the Moolah flashloan principal, and retains ~5.72 WBNB (~$3,421) as profit.
June 4, 2026 — @audit_911 publishes exploit details including attacker address and tx. @clarahacks (Real-time DeFiHacks Intelligence, automated by @d23e_AG) relays full technical analysis including the PoC code showing the core bug and concrete numbers. SlowMist Hacked records incident. No post-mortem published by ApeBond team.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)