← Radar

Incident case file

Sign in to watch

Nimiq HTLC Polygon OpenGSN Meta-Transaction Auth Flaw — $50.5K

Incident date Sep 15, 2026Last updated Sep 24, 2026

1 views

ContainedPolygonMeta-transaction authentication bypassCluster: NIMIQ-POLY-2026-09

Estimated loss

$50.5K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

40%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — liquidity wallet address only known in truncated form (0x24cb...6773); full form never published in any available source.

Linked

Liquidity wallet impersonated/drained (truncated form only): 0x24cb…6773.

Chronology

1 beat
  1. On September 16, 2026, an attacker exploited a flaw in OpenGSN meta-transaction handling within Nimiq's HTLC (hash time-locked contract) system on Polygon. The open/execute functions accepted a spoofed 'from' address without requiring a genuine signature. Using a trivial secret hash (sha256 of 1), the attacker executed the exploit in a single transaction, draining 26,130.64171 USDC, 24,332.489269 USDT0 and 0.661117 USDC.e locked in the affected HTLCs, a total of $50,463, redeeming via a CREATE2-deployed contract. As a precaution, Nimiq suspended all Gas Abstraction stablecoin transactions across its entire ecosystem (both Nimiq Pay and the Nimiq Wallet), not just the affected contract. The full liquidity wallet address involved has never been published; only a truncated form is available in any source.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)