Incident case file
Sign in to watchStrongBlock Abandoned Governance Takeover
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatBackground: StrongBlock, a DeFi Nodes-as-a-Service protocol founded in 2018, had become effectively abandoned over time, with its governance token STRONG trading at near-worthless levels while the protocol's on-chain Governor contract remained active with full administrative privileges intact. T-X: The attacker (0xACBCa357981870f30130B145762d671891CA810c), whose wallet was funded via the RAILGUN privacy protocol's Relay Adapt, accumulates a majority of the now near-worthless STRONG governance/voting token at minimal cost. T0 (August 5, 2026, block 25691519): The attacker calls 'Accept Admin' on the protocol's Upgrader proxy contract (0x75C53809A047c3d422B91Eda50A20914fBe91C61), seizing administrative control after a governance proposal passes without any opposing vote, owing to the protocol's inactive community and abandoned status. Block 25691525: A first contract upgrade is executed. Block 25691527: The attacker executes the actual token theft via a 'Run' function call sourced from contract 0x53cA51Ba980B6475C13d158c1825013cf81038Fc, draining 32,695.76168113 STRONG and 383,447.16729895 STRNGR in a single transaction (0x3ffa7f6da3f0747660917dd331e060e45ffca8a195578ec8db4c9fbc623b0401) — worth approximately $72,000 combined at contemporaneous market prices. Blocks 25691531-25691629: The attacker begins converting the stolen tokens, approving and swapping various amounts through 1inch Aggregation Router V6 and later a dedicated router contract (0x111116053F09d34a7Eae8102887004445176CA11), converting portions into USDT, USDC, BUSD, and ultimately ETH. Block 25691600: The attacker deploys an additional contract labeled 'Migration.' Blocks 25691608-25691610: A second contract upgrade and an additional 'Run' call route a further 14,965.11677945 STRNGR from a separate source ('StrongBlock: Service') to the attacker — a distinct flow from the primary sweep. Block 25691700: A third and final upgrade call is executed against the same Governor proxy contract. Post-incident (August 6, 2026): Security research group Defimon Alerts (operated by Decurity) publishes a full technical breakdown of the exploit, characterizing it precisely: 'the attacker exploited StrongBlock's abandoned on-chain Governor... holding a majority of the now near-worthless STRONG vote token, they pushed a proposal calling setPendingAdmin(attacker).' No official response or statement has been published by any active StrongBlock team representative, consistent with the protocol's fully abandoned operational status. As of this investigation, the attacker's wallet still retains 27.95 ETH (approximately $53,650) in unconverted proceeds, indicating the cash-out process remains only partially complete.
Sources and coverage
- Articlecoinpaper.comhttps://coinpaper.com/33981/strongblock-loses-72k-after-attacker-hijacks-abandoned-governance
- Articleetherscan.iohttps://etherscan.io/tx/0x3ffa7f6da3f0747660917dd331e060e45ffca8a195578ec8db4c9fbc623b0401
- Articleetherscan.iohttps://etherscan.io/address/0xacbca357981870f30130b145762d671891ca810c
- Articleetherscan.iohttps://etherscan.io/tx/0xfb003a0de47e3ed35a3d13d6ba63b213bcc43657e8a2045dcd8e1299e0335578
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)