Incident case file
Sign in to watchSQ Protocol — Hardcoded Owner Backdoor (First Major EIP-7702 Abuse)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — published only on X by SlowMist and Defi_Nerd_sec
Timeline: On May 12, 2026 around 10:11 UTC, an attacker exploited a hardcoded owner backdoor in the SQ Protocol staking contract on BNB Chain (verified contract 0x404404a845fff0201f3a4d419b4839fc419c99f7). The attack chain represents one of the first major documented abuses of EIP-7702: the attacker submitted a type-0x4 transaction with an authorizationList to delegate signing authority and take ownership of the staking contract via the hardcoded backdoor. Once in control, the attacker minted fake staking claim positions, redeemed approximately 296.5K USDT, swept all SQi governance tokens from the contract, and dumped them in the SQi/USDT pool for additional profit (~$346K total). SlowMist and on-chain researcher @Defi_Nerd_sec flagged the exploit shortly after. The incident underscores the new attack surface introduced by EIP-7702 on chains that have activated it.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)