Incident case file
Sign in to watchMolt EVM — Access Control Bypass
Incident date March 7, 2026
0 views
UnknownBaseSmart contract exploitCluster: MOLT-BASE-2026-03
Estimated loss
$127K
Victims identified
more than ten victims identified
Victim group joining is coming soon.
Investigation
60%
Facts and investigation
Attacker: TODO
Funds moved to: Dumped tokens via Aerodrome DEX
TODO
Timeline: Attacker identified that the mint function on Molt EVM was protected by an onlySpawnerToken modifier that could be bypassed. They deployed a malicious contract to circumvent the access control, minted tokens illegitimately, and immediately dumped them through Aerodrome liquidity pools on Base for approximately $127,000.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)