Incident case file
Sign in to watchFlooring Protocol / BitmapPunks — BT404 Ghost Ownership Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — Attacker address not publicly disclosed as of June 13, 2026. Source to check: @0xQuit thread June 8, 2026 / Etherscan search 'Flooring Protocol V2 Exploiter'.
Timeline: On June 8, 2026, an attacker exploited a critical flaw in Flooring Protocol's BT404-style packed ownership and indexing logic. The attack involved passing a high-bit variant of a real token ID (e.g., 2^255+tokenId) to trigger a 'ghost ownership' state: ownership checks and list membership records diverged, meaning the protocol believed the attacker owned an NFT they did not. This allowed an unchecked decrement on the attacker's ownedLength, wrapping their balance to a number larger than all NFTs in the pool. A second underflow in the unwrap/burn path — an unchecked ERC20-side subtraction when the real fpToken balance reached zero — further wrapped the fungible balance to near-infinity. With an effectively unbounded fpToken balance, the attacker dumped the price to near zero and extracted all liquidity from the targeted pools, draining approximately $900K gross. A separate opportunist then scooped up near-worthless fpTokens and redeemed them for underlying NFTs. Security researcher @0xQuit identified a related exploit path threatening additional high-value NFTs and coordinated a whitehat rescue with @coffeedev and @GrailsOTC, recovering approximately $500K in blue-chip NFTs before a second attacker could reach them. Net victim loss: approximately $400K. Attacker address and exploit transaction hash have not been publicly disclosed as of June 13, 2026.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)