Incident case file
Sign in to watchNimiq HTLC Polygon OpenGSN Meta-Transaction Auth Flaw — $50.5K
1 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 16, 2026, an attacker exploited a flaw in OpenGSN meta-transaction handling within Nimiq's HTLC (hash time-locked contract) system on Polygon. The open/execute functions accepted a spoofed 'from' address without requiring a genuine signature. Using a trivial secret hash (sha256 of 1), the attacker executed the exploit in a single transaction, draining 26,130.64171 USDC, 24,332.489269 USDT0 and 0.661117 USDC.e locked in the affected HTLCs, a total of $50,463, redeeming via a CREATE2-deployed contract. As a precaution, Nimiq suspended all Gas Abstraction stablecoin transactions across its entire ecosystem (both Nimiq Pay and the Nimiq Wallet), not just the affected contract. The full liquidity wallet address involved has never been published; only a truncated form is available in any source.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)