Incident case file
Sign in to watchMure (MureDistribution) — Unvalidated Signer Source / SignatureChecker Bypass
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn 21 May 2026 at 04:04:47 UTC (Ethereum block 25141107), an attacker drained the MureDistribution contract in a single transaction (0xb830...c5b798). The root cause was an unvalidated signer source: the _distribute() function accepted a fully attacker-controlled DistributionRecord and only checked that distribution.source supported the PoolMetadata interface, never that the source was an approved Mure pool. The attacker supplied a malicious contract (0x26e5415c...cd467) as both the source and depositor; that contract returned the attacker as the authorized signer, and SignatureChecker.isValidSignatureNow() returned true. With validation bypassed, _transferAssets() executed QUEST transferFrom from the Mure repository (0x29b0a315...1cAc7), which had already granted a standing approval to the MureDistribution proxy. Approximately 4,848,683 QUEST were pulled and swapped on Uniswap V3 (QUEST -> USDC -> ~5.45 ETH, ~$11.7K). Only one distribution contract was affected; no user funds or core payment infrastructure were touched. The incident was flagged publicly by @clarahacks (automated by @d23e_AG, sourcing DefimonAlerts) on 24 May 2026 and recorded by SlowMist Hacked. No project post-mortem has been published.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)