Incident case file
Sign in to watchOMNI404 ERC-404 Dual-Interpretation Flash Loan Exploit — $5.9K Loss
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 11, 2026, an attacker exploited a design flaw in OMNI404 (O404), an ERC-404 hybrid token on Ethereum. The token's transfer() function treated any value of 50 or below as an ERC-721 NFT ID, but the code path also always moved a fixed 1e18 fungible units alongside the NFT regardless of the actual intended transfer amount. Using flash loans and Uniswap V3 exact-output swaps calling transfer(recipient, 1) through transfer(recipient, 21), the attacker received a full 1e18 OMNI404 token per call while the pool's own accounting only debited the tiny wei-level amount it believed was being transferred. This drained approximately 2.4 WETH (~$5,923) from the pool. Trading volume on OMNI404 fell to zero following the exploit's disclosure.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)