← Radar

Incident case file

Sign in to watch

mySwap Starknet Fake-Token CL Pool Exploit

Incident date June 19, 2026

1 views

ClosedStarknetSmart contract exploit — fake token CL pool accounting manipulationCluster: MYS-STK-2026-06

Estimated loss

$305K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: 0x029f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518

Funds moved to: 137.96 ETH + 45,000 USDC + 19,900 USDT + 230,000 STRK (~$305,000) drained from mySwap CL pools, starting with tx 0x1c15c4064cb3d72df27a35dfcd2da17c108abfb8e671428cb9d457f698f588 (block 10,951,100, 07:15:46 UTC). Proceeds subsequently bridged out: ~197.91K USDC bridged (tx 0x374003...d6081), ~19.94K USDT and ~50.9 ETH bridged via Layerswap Bridge; 10 STRK sent directly to a Bybit hot wallet (0x91fea3...a1a26) — a traceable CEX touchpoint.
Fake token deployed by attacker: EVIL (ERC-20) at 0x028C9Acd8EB7Dc1cd7e3dA98da3997cb57bEca3c39D425E90780195Df3A9a49E, flagged 'CONCERNING' by Blockaid. Attacker minted an artificially large EVIL balance (~1.6 x 10^45 EVIL) and approved it to mySwap CL AMM Swap to manipulate pool accounting and extract real assets via collect() calls.

Timeline: On June 19, 2026 at 07:15:46 UTC (block 10,951,100), attacker 0x029f9de5cafb30f55e4a6f4f032e8774958520c1649b3a0441f1354c0b330518 deployed a fake ERC-20 token named 'EVIL' (0x028C9Acd8EB7Dc1cd7e3dA98da3997cb57bEca3c39D425E90780195Df3A9a49E) on Starknet and minted an astronomically large balance to itself within transaction 0x1c15c4064cb3d72df27a35dfcd2da17c108abfb8e671428cb9d457f698f588. The attacker approved this fabricated balance for mySwap's CL AMM Swap contract, which incorrectly trusted the token as having real value, distorting the concentrated-liquidity pool's accounting. Within the same transaction, the attacker called collect() twice, extracting 124.28 ETH (~$209,687) and 12.42 ETH (~$20,969) of real assets from the pool. The attacker continued draining additional pool assets afterward, for a total impact of approximately $305,000 across 137.96 ETH, 45,000 USDC, 19,900 USDT, and 230,000 STRK. Security firm F12 Security detected and publicly disclosed the exploit the same day, describing it as 'a real permissionless exploit, not a rug.' On-chain tracing confirms the attacker subsequently moved proceeds off-chain: ~197.91K USDC bridged out (tx 0x374003...d6081), ~19.94K USDT and ~50.9 ETH bridged via Layerswap Bridge, and a smaller 10 STRK transaction sent directly to a Bybit exchange hot wallet (0x91fea3...a1a26). No recovery has been reported.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)