Incident case file
Sign in to watchmySwap Starknet Fake-Token CL Pool Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x029f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518
Timeline: On June 19, 2026 at 07:15:46 UTC (block 10,951,100), attacker 0x029f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518 deployed a fake ERC-20 token named 'EVIL' (0x028C9Acd8EB7Dc1cd7e3dA98da3997cb57bEca3c39D425E90780195Df3A9a49E) on Starknet and minted an astronomically large balance to itself within transaction 0x1c15c4064cb3d72df27a35dfcd2da17c108abfb8e671428cb9d457f698f588. The attacker approved this fabricated balance for mySwap's CL AMM Swap contract, which incorrectly trusted the token as having real value, distorting the concentrated-liquidity pool's accounting. Within the same transaction, the attacker called collect() twice, extracting 124.28 ETH (~$209,687) and 12.42 ETH (~$20,969) of real assets from the pool. The attacker continued draining additional pool assets afterward, for a total impact of approximately $305,000 across 137.96 ETH, 45,000 USDC, 19,900 USDT, and 230,000 STRK. Security firm F12 Security detected and publicly disclosed the exploit the same day, describing it as 'a real permissionless exploit, not a rug.' On-chain tracing confirms the attacker subsequently moved proceeds off-chain: ~197.91K USDC bridged out (tx 0x374003...d6081), ~19.94K USDT and ~50.9 ETH bridged via Layerswap Bridge, and a smaller 10 STRK transaction sent directly to a Bybit exchange hot wallet (0x91fea3...a1a26). No recovery has been reported.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)