Incident case file
Sign in to watchGondi V3 NFT Lending — PurchaseBundler Access Control Flaw
Incident date 2026-03-09
0 views
ResolvedEthereumSmart contract exploitCluster: GONDI-ETH-2026-03
Estimated loss
$230K
Victims identified
more than ten victims identified
Victim group joining is coming soon.
Investigation
80%
Facts and investigation
Ledger
Attacker
TODO
Funds moved to
TODO
Linked
TODO
Chronology
1 beatAttacker exploited the PurchaseBundler contract in Gondi V3, an NFT lending protocol. The vulnerable function failed to verify that msg.sender was the legitimate borrower, allowing unauthorized purchases. The attacker stole 78 high-value NFTs including Art Blocks, Doodles, and Beeple pieces worth approximately $230,000. The Gondi team disabled the affected contract following the exploit.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)