Incident case file
Sign in to watchRoyal — Legacy Royalties Contract Zero-Value Reward Inflation
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xbd829aa63311bb1e3c0ea58a7193364de670bd56
Timeline: T0 (June 23, 2026, 16:27:52 UTC, Polygon block 89018051): Attacker address 0xbd829aa63311bb1e3c0ea58a7193364de670bd56 executes a flash-swap of 2,638.089539 USDC via a Uniswap V2 pair, then issues 100 zero-value ERC-1155 transfers through attack contract 0x7fd7be7bc8a26bd6a98b10683912c604af8bca52 against the legacy Royalties proxy 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7, exploiting flawed settlement logic to artificially stack reward records and claim an inflated ('tier-42 LDA') share. T0+seconds: 263,808.953900 USDC extracted from the Royalties contract in a single transaction (0x7a92106f145045b7a2bdce60a22109739f9b0cd0185bf16ff83fd1fac98cb42e); flash-swap repaid, leaving the attacker with ~261,162.93 USDC net. T+1 day (June 24, 2026): CertiK publishes a public alert confirming the exploit and root cause (zero-value transfer reward-stacking against flawed settlement logic); forensic write-up published by DARKNAVY corroborating the mechanism and figures. Status: no statement from Royal, no patch, no recovery as of report compilation (last documented activity June 24, 2026).
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)