← Radar

Incident case file

Sign in to watch

Gondi V3 NFT Lending — PurchaseBundler Access Control Flaw

Incident date March 9, 2026

0 views

ResolvedEthereumSmart contract exploitCluster: GONDI-ETH-2026-03

Estimated loss

$230K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

80%

Facts and investigation

Attacker: TODO

Funds moved to: TODO
TODO

Timeline: Attacker exploited the PurchaseBundler contract in Gondi V3, an NFT lending protocol. The vulnerable function failed to verify that msg.sender was the legitimate borrower, allowing unauthorized purchases. The attacker stole 78 high-value NFTs including Art Blocks, Doodles, and Beeple pieces worth approximately $230,000. The Gondi team disabled the affected contract following the exploit.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)