Incident case file
Sign in to watchToken of Power — Dividend Accounting Exploit
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xff8ef7bc455a57e5893232203052ce0232b39fa2 (Pre-funded via Tornado Cash withdrawals June 9 08:xx UTC; post-exploit deposits back into Tornado Cash)
Timeline: On June 9, 2026, an attacker exploited a dividend accounting flaw in the Token of Power protocol on Ethereum. Beginning at approximately 08:00 UTC, the attacker pre-funded their wallet by withdrawing ~60 previous Tornado Cash deposits. At 12:32:47 UTC (Block 25279891), they deployed a malicious constructor contract (method 0x60a06040) that exploited the protocol's dividend distribution logic — specifically an incorrect operation order where the baseline snapshot and distribution calculation occurred before the user's stake was credited. This allowed the attacker to receive dividends on a payout their own deposit had just created, amplified by the ratio between the new deposit and the old total. A net drain of 662.9 ETH ($1,112,903) was extracted from the protocol reward pool in a single transaction. Within four minutes, the attacker initiated Tornado Cash deposits totaling over 845 ETH. Funds are considered unrecoverable.
Sources and coverage
- Articleetherscan.iohttps://etherscan.io/tx/0xdf4dad0b05fdfca6c6f400c509805d4c937ab407243f6832b2a72a19940f56e1
- Articleetherscan.iohttps://etherscan.io/address/0xff8ef7bc455a57e5893232203052ce0232b39fa2
- Articleetherscan.iohttps://etherscan.io/address/0x25c68c44a96518294f5b47d758f98309c6729a21
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)