Incident case file
Sign in to watchONTR — onlyOwner Accepts address(0) + Hidden Balance-Grant Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker EOA: 0xe806b37a9f965bd9d54aadf9560c78957550b760. Attack contract (created in the tx): 0xd7a33e89abc1ac5b2497d9589c81784a2bc52491.
Timeline: Around 28-29 May 2026, an attacker stole 49.4801 WETH (~$98,315) from the ONTR token on BNB Smart Chain. The root cause was a flawed onlyOwner modifier, require(hazeDeer == address(0) || hazeDeer == _msgSender()): because the owner field (hazeDeer) was address(0), any caller passed the authorization check. The attacker (EOA 0xe806b37a...0b760, via attack contract 0xd7a33e89...52491) called transferOwnership() to become owner, then desertJasper() to queue a hidden balance, then glenFlash()/ashBud() to inflate its balance by 1e30 base units without incrementing totalSupply (a free, mint-event-less inflation), and finally transferred the inflated ONTR into the ONTR/WETH PancakeSwap pair (0xd46d89f4...83fd) and swapped for real WETH. SlowMist publicised the incident on 29 May; its X post specifies the wei-precise loss of 49.4801 WETH (~$98,315), which is used here over the rounded $98,200 in the SlowMist Hacked feed. Recovery: 0%.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)