← Radar

Incident case file

Sign in to watch

SQ Protocol — Hardcoded Owner Backdoor (First Major EIP-7702 Abuse)

Incident date May 12, 2026

0 views

UnknownBSCEIP-7702 abuse / Hardcoded backdoorCluster: SQ-BSC-2026-05

Estimated loss

$346.1K

Victims identified

1
Victim group joining is coming soon.

Investigation

55%

Facts and investigation

Attacker: TODO — published only on X by SlowMist and Defi_Nerd_sec

Funds moved to: ~296.5K USDT redeemed + SQi tokens swept and dumped in SQi/USDT pool; downstream destinations not publicly traced
Victim staking contract: 0x404404a845fff0201f3a4d419b4839fc419c99f7 (BscScan-verified, confirmed by SlowMist). The attacker submitted a type-0x4 transaction with an authorizationList — abusing the newly-active EIP-7702 primitive on BNB Chain — to take ownership of the staking contract via a hardcoded backdoor. They then minted fake staking claim positions, redeemed ~296.5K USDT, swept all SQi tokens from the contract, and dumped them in the SQi/USDT liquidity pool for additional profit.

Timeline: On May 12, 2026 around 10:11 UTC, an attacker exploited a hardcoded owner backdoor in the SQ Protocol staking contract on BNB Chain (verified contract 0x404404a845fff0201f3a4d419b4839fc419c99f7). The attack chain represents one of the first major documented abuses of EIP-7702: the attacker submitted a type-0x4 transaction with an authorizationList to delegate signing authority and take ownership of the staking contract via the hardcoded backdoor. Once in control, the attacker minted fake staking claim positions, redeemed approximately 296.5K USDT, swept all SQi governance tokens from the contract, and dumped them in the SQi/USDT pool for additional profit (~$346K total). SlowMist and on-chain researcher @Defi_Nerd_sec flagged the exploit shortly after. The incident underscores the new attack surface introduced by EIP-7702 on chains that have activated it.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)