← Radar

Incident case file

Sign in to watch

Royal — Legacy Royalties Contract Zero-Value Reward Inflation

Incident date June 23, 2026

1 views

ActivePolygonReward accounting exploit / flash-loan amplificationCluster: ROYAL-NFT-2026-06

Estimated loss

$261.2K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 0xbd829aa63311bb1e3c0ea58a7193364de670bd56

Funds moved to: Attacker flash-swapped 2,638.089539 USDC via Uniswap V2 pair 0x6e7a5fafcec6bb1e78bae2a1f0b612012bf14827, submitted 100 zero-value ERC-1155 transfers (tier-42 LDA) through helper/attack contract 0x7fd7be7bc8a26bd6a98b10683912c604af8bca52 to stack reward records, then extracted 263,808.953900 USDC from the Royalties contract. After repaying the flash-swap, net proceeds retained: ~261,162.93 USDC (~$261,200). Exploit transaction: 0x7a92106f145045b7a2bdce60a22109739f9b0cd0185bf16ff83fd1fac98cb42e (P
Victim contract — Royalties proxy: 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7. Implementation contract: 0x1e0598614d9168a657cb57bd038dfd71812c9074. Royal1155LDA proxy: 0x7c885c4bfd179fb59f1056fbea319d579a278075. CertiK verbatim (June 24, 2026): 'We have seen a $263K exploit on the Royalties contract at 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7 on Polygon. Through 100 zero-value transfers, the attacker exploited flawed settlement logic to stack reward records and claim 100X reward.' This is a

Timeline: T0 (June 23, 2026, 16:27:52 UTC, Polygon block 89018051): Attacker address 0xbd829aa63311bb1e3c0ea58a7193364de670bd56 executes a flash-swap of 2,638.089539 USDC via a Uniswap V2 pair, then issues 100 zero-value ERC-1155 transfers through attack contract 0x7fd7be7bc8a26bd6a98b10683912c604af8bca52 against the legacy Royalties proxy 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7, exploiting flawed settlement logic to artificially stack reward records and claim an inflated ('tier-42 LDA') share. T0+seconds: 263,808.953900 USDC extracted from the Royalties contract in a single transaction (0x7a92106f145045b7a2bdce60a22109739f9b0cd0185bf16ff83fd1fac98cb42e); flash-swap repaid, leaving the attacker with ~261,162.93 USDC net. T+1 day (June 24, 2026): CertiK publishes a public alert confirming the exploit and root cause (zero-value transfer reward-stacking against flawed settlement logic); forensic write-up published by DARKNAVY corroborating the mechanism and figures. Status: no statement from Royal, no patch, no recovery as of report compilation (last documented activity June 24, 2026).

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)