← Radar

Incident case file

Sign in to watch

OMNI404 ERC-404 Dual-Interpretation Flash Loan Exploit — $5.9K Loss

Incident date Sep 10, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumERC-404 dual ID/amount interpretation bugCluster: OMNI404-ETH-2026-09

Estimated loss

$5.9K

Affected users

1
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0xfb26db4eab18cb50d29ff431888dd643a7e9c9f8

Funds moved to

2.4 WETH drained from the Uniswap V3 liquidity pool via a flash-loan-assisted exact-output swap loop.

Linked

Attacker: 0xfb26db4eab18cb50d29ff431888dd643a7e9c9f8. Victim pool: 0xb3f613b9bc84ddb29d78fa4685b01d98412bba0b. Vulnerable contract: 0xd5c02bb3e40494d4674778306da43a56138a383e.

Chronology

1 beat
  1. On September 11, 2026, an attacker exploited a design flaw in OMNI404 (O404), an ERC-404 hybrid token on Ethereum. The token's transfer() function treated any value of 50 or below as an ERC-721 NFT ID, but the code path also always moved a fixed 1e18 fungible units alongside the NFT regardless of the actual intended transfer amount. Using flash loans and Uniswap V3 exact-output swaps calling transfer(recipient, 1) through transfer(recipient, 21), the attacker received a full 1e18 OMNI404 token per call while the pool's own accounting only debited the tiny wei-level amount it believed was being transferred. This drained approximately 2.4 WETH (~$5,923) from the pool. Trading volume on OMNI404 fell to zero following the exploit's disclosure.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)