← Radar

Incident case file

Sign in to watch

Superfortune ($GUA) — Multisig Execution Tampering / Signer-Key Leak

Incident date May 27, 2026

0 views

ActiveBNB Smart ChainMultisig manipulation / signer-key leakCluster: SF-MSIG-2026-05

Estimated loss

$5.7M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

60%

Facts and investigation

Attacker: Hacker destination address (recipient of the diverted unlock): 0x70AE678b457C5E1b3fD7AD9537F234dFc1795C15. Proceeds (2,784 ETH) stored across three wallets: 0x111b78A86C16dBD4261FCb5C7D3A9dAF25E2b589, 0x7b8f28Ff2E1D4DF2D8ddD1daBaFf8c3E58FE841C, 0xfA4cB6aDD9DA4a4b714541b98fD4b2E3DA86B7c8.

Funds moved to: 14,981,000 GUA (~$15.18M nominal at the time) were dumped on-chain for 2,784 ETH (~$5.66M realised) and stored across three attacker wallets (0x111b78A8..., 0x7b8f28Ff..., 0xfA4cB6aD...). No recovery as of cutoff.
GUA token (BEP-20): 0xA5C8e1513B6A08334b479fe4D71F1253259469BE. Token creator: 0xa89FD7b64aa4bf4bc63333043714d6a5e5cdb7bb (created 213 days prior). Intended (legitimate) airdrop-claim address: 0x70ae7D3DECfB4C3aE996fb1c07092566F73D5c15. Diverted hacker destination: 0x70AE678b457C5E1b3fD7AD9537F234dFc1795C15 (note it matches the first and last 4 characters of the intended address -- the classic address-poisoning signature, although the team rules out poisoning because the hacker address had no pr

Timeline: On 27 May 2026, during a multisig transaction intended to release unlocked GUA tokens into Superfortune's airdrop-claim contract (0x70ae7D3D...5c15), the destination address was altered to an attacker-controlled wallet (0x70AE678b...5C15), which matches the first and last four characters of the intended address. About 14,981,000 GUA (~$15.18M nominal at the time) were diverted and immediately dumped on-chain for 2,784 ETH (~$5.66M realised), crashing GUA roughly 70-76% within 24 hours (from an ATH of $1.68 on 25 May to a low near $0.24). The proceeds were stored across three attacker wallets. Superfortune (@SUPERFORTUNE888) published an investigation note the same day stating that initial findings point to an address manipulation through the multisig transaction, that the hacker address had no prior interaction with Superfortune (so address poisoning is unlikely as the vector), and that internal procedures account for poisoning attempts; the team's working hypothesis is a signer private-key leak, not an inside job. EmberCN published the on-chain reconstruction and the three holding wallets. The project contacted authorities and incident-response teams. SlowMist Hacked tags the method as 'Multisig Address Tampering' and lists the nominal $15.18M; the realised loss of $5.66M (2,784 ETH) is used as the headline figure, with the $15.18M nominal noted. Superfortune is a Manta-incubated project (TGE 27 Nov 2025; pre-attack market cap ~$90.4M, circulating 125M of 1B GUA). Recovery: 0%; investigation active.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)