Incident case file
Sign in to watchONTR — onlyOwner Accepts address(0) + Hidden Balance-Grant Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAround 28-29 May 2026, an attacker stole 49.4801 WETH (~$98,315) from the ONTR token on BNB Smart Chain. The root cause was a flawed onlyOwner modifier, require(hazeDeer == address(0) || hazeDeer == _msgSender()): because the owner field (hazeDeer) was address(0), any caller passed the authorization check. The attacker (EOA 0xe806b37a...0b760, via attack contract 0xd7a33e89...52491) called transferOwnership() to become owner, then desertJasper() to queue a hidden balance, then glenFlash()/ashBud() to inflate its balance by 1e30 base units without incrementing totalSupply (a free, mint-event-less inflation), and finally transferred the inflated ONTR into the ONTR/WETH PancakeSwap pair (0xd46d89f4...83fd) and swapped for real WETH. SlowMist publicised the incident on 29 May; its X post specifies the wei-precise loss of 49.4801 WETH (~$98,315), which is used here over the rounded $98,200 in the SlowMist Hacked feed. Recovery: 0%.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)