Incident case file
Sign in to watchMure (MureDistribution) — Unvalidated Signer Source / SignatureChecker Bypass
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x08096e9ae70D7C5F2707b203A7801b75d1412156 (EOA / funder). Attack contracts created in the tx: 0x2b896760f8ad2ecf58ef93bdf71ac5e85c2b7f63 and 0x26e5415c5ba86b4a521aaebf538623b9f32cd467 (fake source/signer).
Timeline: On 21 May 2026 at 04:04:47 UTC (Ethereum block 25141107), an attacker drained the MureDistribution contract in a single transaction (0xb830...c5b798). The root cause was an unvalidated signer source: the _distribute() function accepted a fully attacker-controlled DistributionRecord and only checked that distribution.source supported the PoolMetadata interface, never that the source was an approved Mure pool. The attacker supplied a malicious contract (0x26e5415c...cd467) as both the source and depositor; that contract returned the attacker as the authorized signer, and SignatureChecker.isValidSignatureNow() returned true. With validation bypassed, _transferAssets() executed QUEST transferFrom from the Mure repository (0x29b0a315...1cAc7), which had already granted a standing approval to the MureDistribution proxy. Approximately 4,848,683 QUEST were pulled and swapped on Uniswap V3 (QUEST -> USDC -> ~5.45 ETH, ~$11.7K). Only one distribution contract was affected; no user funds or core payment infrastructure were touched. The incident was flagged publicly by @clarahacks (automated by @d23e_AG, sourcing DefimonAlerts) on 24 May 2026 and recorded by SlowMist Hacked. No project post-mortem has been published.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)