← Radar

Incident case file

Sign in to watch

Asterix Labs ($ASTX) — DN404 Token ID Overflow, 242-Trade Pool Drain

Incident date June 8, 2026

1 views

ActiveEthereumNFT contract exploit / DN404 token ID overflowCluster: AST-ETH-2026-06

Estimated loss

$40K

Victims identified

1
Victim group joining is coming soon.

Investigation

35%

Facts and investigation

Attacker: TODO — Attacker address not publicly disclosed as of June 13, 2026. Source to check: Etherscan token transfers for 0x0000000000ca73a6df4c58b84c5b4b847fe8ff39 (ASTX) around June 7, 2026 19:50–20:10 UTC — look for address executing 242 rapid transactions.

Funds moved to: ~30 ETH (~$40,000) drained from Uniswap v4 ASTX/ETH liquidity pool via 242 automated transactions. Destination address unknown pending attacker EOA identification. ASTX contract is immutable — no patch possible. Team planning full token migration.
ASTX token contract: 0x0000000000ca73a6df4c58b84c5b4b847fe8ff39 Uniswap v4 pool affected (ASTX/ETH — exact pool address TODO). Exploit tx: TODO — first of 242 transactions starting June 7, 2026 19:56:11 UTC (reported as June 8 03:56:11 AM UTC+8 by SSR). Attack pattern: sell 1 ASTX for ETH (Phase 1) → settle trade debt using forged high-bit NFT ID 2^255+tokenId (Phase 2) → use leftover stale approval to pull real NFT back from pool (Phase 3) → repeat 242 times. Net: attacker retains ETH

Timeline: On June 8, 2026 at 03:56:11 AM UTC+8 (June 7, 19:56:11 UTC), an attacker executed a highly automated campaign of 242 transactions against the Asterix Labs ($ASTX) Uniswap v4 liquidity pool on Ethereum, draining approximately 30 ETH (~$40,000). The root cause was a missing constraint in an early version of the DN404 library: token IDs for approvals were not restricted to 32 bits, allowing the attacker to craft approvals using IDs with high bits set (e.g., 2^255+4598) that would alias back to a real NFT ID in the packed ownership accounting. The attacker exploited this by repeatedly: (1) selling one ASTX token into the pool to receive ETH, (2) settling the resulting trade debt using a forged NFT ID that collided with a real token in the packed records, and (3) using the surviving stale approval to immediately extract the real NFT back from the pool — leaving the pool short on ETH each round while ASTX supply appeared unchanged. The team confirmed the attack involved AI-assisted fuzzing to identify the unconventional logic path. Because the ASTX contract is fully immutable, no patch is possible. Asterix / Super Secret Rare has advised users to stop interacting with the current pool and token, and committed to migrating to a secure redeployment. Attacker address and first exploit transaction hash remain unidentified as of June 13, 2026.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)