← Radar

Incident case file

Sign in to watch

Mure (MureDistribution) — Unvalidated Signer Source / SignatureChecker Bypass

Incident date May 21, 2026

0 views

ClosedEthereumAccess control / Unvalidated signer sourceCluster: MURE-SIG-2026-05

Estimated loss

$11.7K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: 0x08096e9ae70D7C5F2707b203A7801b75d1412156 (EOA / funder). Attack contracts created in the tx: 0x2b896760f8ad2ecf58ef93bdf71ac5e85c2b7f63 and 0x26e5415c5ba86b4a521aaebf538623b9f32cd467 (fake source/signer).

Funds moved to: 4,848,683 QUEST drained from the Mure repository, swapped via Uniswap V3 (QUEST -> USDC -> ETH) for ~5.45 ETH (~$11.7K), routed back to attacker EOA 0x08096e9ae70D7C5F2707b203A7801b75d1412156.
Attacker EOA: 0x08096e9ae70D7C5F2707b203A7801b75d1412156. Attack contract #1 (created in tx): 0x2b896760f8ad2ecf58ef93bdf71ac5e85c2b7f63. Attack contract #2 / fake source-signer (created in tx): 0x26e5415c5ba86b4a521aaebf538623b9f32cd467. Vulnerable MureDistribution proxy: 0x365083717eFB17F3895290BA38f20F568C7A4D8a. Drained repository: 0x29b0a315924E05aC0c898a63D96daA33Cfd1cAc7. QUEST token: 0x1Fc122FE8b6Fa6b8598799baF687539b5D3B2783. Uniswap V3 Router: 0xE592427A0AEce92De3Edee1F18E0157C05861564

Timeline: On 21 May 2026 at 04:04:47 UTC (Ethereum block 25141107), an attacker drained the MureDistribution contract in a single transaction (0xb830...c5b798). The root cause was an unvalidated signer source: the _distribute() function accepted a fully attacker-controlled DistributionRecord and only checked that distribution.source supported the PoolMetadata interface, never that the source was an approved Mure pool. The attacker supplied a malicious contract (0x26e5415c...cd467) as both the source and depositor; that contract returned the attacker as the authorized signer, and SignatureChecker.isValidSignatureNow() returned true. With validation bypassed, _transferAssets() executed QUEST transferFrom from the Mure repository (0x29b0a315...1cAc7), which had already granted a standing approval to the MureDistribution proxy. Approximately 4,848,683 QUEST were pulled and swapped on Uniswap V3 (QUEST -> USDC -> ~5.45 ETH, ~$11.7K). Only one distribution contract was affected; no user funds or core payment infrastructure were touched. The incident was flagged publicly by @clarahacks (automated by @d23e_AG, sourcing DefimonAlerts) on 24 May 2026 and recorded by SlowMist Hacked. No project post-mortem has been published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)