← Radar

Incident case file

Sign in to watch

SubQuery Network — Settings Contract Missing Access Control

Incident date April 12, 2026

0 views

ResolvedBaseSmart contract exploitCluster: SUBQUERY-BASE-2026-04

Estimated loss

$134K

Victims identified

272
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: TODO — addresses not enumerated in published post-mortem

Funds moved to: TODO
Compromised contract: Settings contract on Base (missing onlyOwner on setContractAddress() and setBatchAddress()). Block 44,590,469. Attacker deployed two ephemeral helper contracts. Original StakingManager and RewardsDistributor restored post-incident.

Timeline: April 12, 2026: Attacker deploys two ephemeral contracts on Base, abuses the absence of any owner/role guard on Settings.setBatchAddress() and Settings.setContractAddress(). Temporarily rewires the protocol StakingManager and RewardsDistributor entries to attacker-controlled helpers. 04:35 UTC: TX5 (small Treasury probe). 05:04 UTC: TX1 drains ~218M SQT from pooled Staking. 05:28 UTC: TX2 drains ~11.8M SQT additional. 06:05 UTC: TX4 drains ~22.8M SQT from RewardsBooster. TX3 drains 272 individual stakers/delegators. Total drain: 382,433,441 SQT (~$134,000) across 5 transactions. Same day: SubQuery team identifies issue, restores original contract addresses, deploys onlyOwner patch. April 13: Full disclosure and 100% compensation plan published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)