Incident case file
Sign in to watchAsterix Labs ($ASTX) — DN404 Token ID Overflow, 242-Trade Pool Drain
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — Attacker address not publicly disclosed as of June 13, 2026. Source to check: Etherscan token transfers for 0x0000000000ca73a6df4c58b84c5b4b847fe8ff39 (ASTX) around June 7, 2026 19:50–20:10 UTC — look for address executing 242 rapid transactions.
Timeline: On June 8, 2026 at 03:56:11 AM UTC+8 (June 7, 19:56:11 UTC), an attacker executed a highly automated campaign of 242 transactions against the Asterix Labs ($ASTX) Uniswap v4 liquidity pool on Ethereum, draining approximately 30 ETH (~$40,000). The root cause was a missing constraint in an early version of the DN404 library: token IDs for approvals were not restricted to 32 bits, allowing the attacker to craft approvals using IDs with high bits set (e.g., 2^255+4598) that would alias back to a real NFT ID in the packed ownership accounting. The attacker exploited this by repeatedly: (1) selling one ASTX token into the pool to receive ETH, (2) settling the resulting trade debt using a forged NFT ID that collided with a real token in the packed records, and (3) using the surviving stale approval to immediately extract the real NFT back from the pool — leaving the pool short on ETH each round while ASTX supply appeared unchanged. The team confirmed the attack involved AI-assisted fuzzing to identify the unconventional logic path. Because the ASTX contract is fully immutable, no patch is possible. Asterix / Super Secret Rare has advised users to stop interacting with the current pool and token, and committed to migrating to a secure redeployment. Attacker address and first exploit transaction hash remain unidentified as of June 13, 2026.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)