← Radar

Incident case file

Sign in to watch

Flooring Protocol / BitmapPunks — BT404 Ghost Ownership Exploit

Incident date June 8, 2026

1 views

ContainedEthereumNFT contract exploit / BT404 bit-pack integer overflowCluster: FLO-ETH-2026-06

Estimated loss

$900K

Victims identified

1
Victim group joining is coming soon.

Investigation

45%

Facts and investigation

Attacker: TODO — Attacker address not publicly disclosed as of June 13, 2026. Source to check: @0xQuit thread June 8, 2026 / Etherscan search 'Flooring Protocol V2 Exploiter'.

Funds moved to: Gross drain ~$900K from Flooring pools via unbounded fpToken balance. ~$500K in NFTs (29 BAYC, 4 MAYC, 1 BAKC, 2 CryptoPunks, 1 Azuki, 2 Elementals, 26 Captains, 1 Moonbird, 2 Doodles) rescued by whitehat team (@0xQuit, @coffeedev, @GrailsOTC) using the same bug class defensively. Exploiters retain remaining NFTs. Net victim loss: ~$400K.
TODO — Exploit tx hash not publicly disclosed. Whitehat rescue team: @0xQuit, @coffeedev, @GrailsOTC / @mfigge. Secondary opportunist actor separately acquired cheap fpTokens from depleted pools and redeemed for underlying NFTs. @0xQuit confirmed the exploiters still hold additional NFTs as of June 8. Users warned not to deposit further NFTs into Flooring Protocol.

Timeline: On June 8, 2026, an attacker exploited a critical flaw in Flooring Protocol's BT404-style packed ownership and indexing logic. The attack involved passing a high-bit variant of a real token ID (e.g., 2^255+tokenId) to trigger a 'ghost ownership' state: ownership checks and list membership records diverged, meaning the protocol believed the attacker owned an NFT they did not. This allowed an unchecked decrement on the attacker's ownedLength, wrapping their balance to a number larger than all NFTs in the pool. A second underflow in the unwrap/burn path — an unchecked ERC20-side subtraction when the real fpToken balance reached zero — further wrapped the fungible balance to near-infinity. With an effectively unbounded fpToken balance, the attacker dumped the price to near zero and extracted all liquidity from the targeted pools, draining approximately $900K gross. A separate opportunist then scooped up near-worthless fpTokens and redeemed them for underlying NFTs. Security researcher @0xQuit identified a related exploit path threatening additional high-value NFTs and coordinated a whitehat rescue with @coffeedev and @GrailsOTC, recovering approximately $500K in blue-chip NFTs before a second attacker could reach them. Net victim loss: approximately $400K. Attacker address and exploit transaction hash have not been publicly disclosed as of June 13, 2026.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)