Incident case file
Sign in to watchShapeShift FOX Colony — MetaTransaction Self-Call Exploit (Plus Copycat)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28 (primary) + unidentified copycat
Timeline: On May 13, 2026, an attacker exploited a MetaTransaction self-call vulnerability in a ShapeShift FOX Colony deployment on Arbitrum. The exploit abused the executeMetaTransaction function: by meta-signing a transaction where msg.sender == the contract itself, the attacker bypassed the DSAuth modifier protecting privileged functions (the auth modifier auto-trusted self-calls). The attacker then repointed the Colony resolver to a malicious contract and used delegatecall to drain USDC and FOX governance tokens (~$132.7K). All four malicious contracts (temporary attack, malicious resolver, malicious drain implementation) were deployed and executed within a single transaction via the constructor of the temporary contract. SlowMist published a detailed post-mortem. MistTrack labeled the primary attacker EOA 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28 as 'ShapeShift Exploiter' and traced fund movements through Relay.link, Tornado.Cash, LI.FI, and Spark.fi Saving. Shortly after, a copycat attacker exploited the same vector for an additional ~$50K, raising the cumulative loss to ~$182,700. Blockaid published a critical warning that any Colony Network deployment exposing executeMetaTransaction on an EtherRouter pattern is potentially exposed to the same exploit class.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/13/shapeshift-fox-colony-loses-132k-in-smart-contract-exploit-on-arbitrum/
- Articlecrypto.newshttps://crypto.news/blockaid-warns-of-active-smart-contract-exploit/
- Articleslowmist.medium.comhttps://slowmist.medium.com/analysis-of-the-exploit-trust-chain-flaw-in-shapeshift-fox-colony-authorization-mechanism-b35a61865a80
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)