Incident case file
Sign in to watchGondi V3 NFT Lending — PurchaseBundler Access Control Flaw
Incident date March 9, 2026
0 views
ResolvedEthereumSmart contract exploitCluster: GONDI-ETH-2026-03
Estimated loss
$230K
Victims identified
more than ten victims identified
Victim group joining is coming soon.
Investigation
80%
Facts and investigation
Attacker: TODO
Funds moved to: TODO
TODO
Timeline: Attacker exploited the PurchaseBundler contract in Gondi V3, an NFT lending protocol. The vulnerable function failed to verify that msg.sender was the legitimate borrower, allowing unauthorized purchases. The attacker stole 78 high-value NFTs including Art Blocks, Doodles, and Beeple pieces worth approximately $230,000. The Gondi team disabled the affected contract following the exploit.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)