← Radar

Incident case file

Sign in to watch

ShapeShift FOX Colony — MetaTransaction Self-Call Exploit (Plus Copycat)

Incident date May 13, 2026

0 views

ActiveArbitrumMetaTransaction / Self-call exploitCluster: FOX-ARB-2026-05

Estimated loss

$182.7K

Victims identified

2
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28 (primary) + unidentified copycat

Funds moved to: MistTrack-traced destinations: Relay.link ($4,368.08), Tornado.Cash ($218.09 initial gas + outflows), LI.FI ($137,073.66), then Spark.fi Saving
Primary attacker EOA: 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28 (MistTrack-labeled 'ShapeShift Exploiter'). Victim contract (EtherRouter Colony): 0x5c59d0ec51729e40c413903be6a4612f4e2452da. Temporary attack contract: 0x835a701fd76b96a76ee84de037d41f059ee29f5c. Malicious resolver: 0x4e321af09012e15a67756522187c05b108b7ee0a. Malicious drain implementation: 0x0b971e0a8ecc7d5b2465c903cf75aeaedbfc39e2. The primary drain extracted $132.7K in USDC and FOX governance tokens. A copycat then exploited th

Timeline: On May 13, 2026, an attacker exploited a MetaTransaction self-call vulnerability in a ShapeShift FOX Colony deployment on Arbitrum. The exploit abused the executeMetaTransaction function: by meta-signing a transaction where msg.sender == the contract itself, the attacker bypassed the DSAuth modifier protecting privileged functions (the auth modifier auto-trusted self-calls). The attacker then repointed the Colony resolver to a malicious contract and used delegatecall to drain USDC and FOX governance tokens (~$132.7K). All four malicious contracts (temporary attack, malicious resolver, malicious drain implementation) were deployed and executed within a single transaction via the constructor of the temporary contract. SlowMist published a detailed post-mortem. MistTrack labeled the primary attacker EOA 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28 as 'ShapeShift Exploiter' and traced fund movements through Relay.link, Tornado.Cash, LI.FI, and Spark.fi Saving. Shortly after, a copycat attacker exploited the same vector for an additional ~$50K, raising the cumulative loss to ~$182,700. Blockaid published a critical warning that any Colony Network deployment exposing executeMetaTransaction on an EtherRouter pattern is potentially exposed to the same exploit class.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)