← Radar

Incident case file

Sign in to watch

MoneyMon (LegendaryMoneyMonNft) — ecrecover address(0) Signature Bypass

Incident date May 29, 2026

0 views

ClosedBNB Smart ChainSmart contract exploit / signature verification bypassCluster: MMON-SIG-2026-05

Estimated loss

$85.5K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: Attacker EOA: 0xe1582248c593df4b367e131922438fec9d76e787.

Funds moved to: All reward tokens drained from the LegendaryMoneyMonNft contract and swapped for ~85,519.47 USDT on PancakeSwap. Onward movement not detailed in available sources.
Attacker EOA: 0xe1582248c593df4b367e131922438fec9d76e787. Vulnerable / victim contract (LegendaryMoneyMonNft): 0x92d60629ff5d53a0098b51e9b1d59546d1d8e5b6. Exploited function (verbatim, with the contract's own typo): cliamRewred. The exploit tx hash and exact UTC timestamp are retrievable via the attacker EOA on BscScan.

Timeline: On 29 May 2026, an attacker drained ~$85,519.47 (in USDT) from the LegendaryMoneyMonNft contract on BNB Smart Chain via a signature-verification bypass. The contract's verify() function returned recoverSigner(...) == admin, and recoverSigner used ecrecover without rejecting the address(0) return case; separately, changeadmin() allowed setting admin to the zero address. The attacker set admin to address(0), then submitted an invalid signature (r=0, s=0, v=27), which ecrecover reduces to address(0), so the == admin check passed. With authorization bypassed, the attacker called the (misspelled) cliamRewred function to arbitrarily claim and drain all reward tokens from the contract (0x92d60629...e5b6), swapping them for ~85,519.47 USDT on PancakeSwap. SlowMist detected and publicised the incident the same day. Recovery: 0%.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)