← Radar

Incident case file

Sign in to watch

Veil Cash (Veil Protocol) — Groth16 Verifier Misconfiguration (delta2 == gamma2)

Incident date February 20, 2026

0 views

ClosedBaseSmart contract exploit / ZK verifier misconfigurationCluster: VEIL-ZK-2026-02

Estimated loss

$5K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: Attack contract 0x5f68ad46f500949fa7e94971441f279a85cb3354 (deployed within the exploit transaction); withdrawal recipient 0x49a7ca88094b59b15eaa28c8c6d9bfab78d5f903. Funding EOA not enumerated in available sources.

Funds moved to: 2.9 ETH withdrawn to recipient 0x49a7ca88094b59b15eaa28c8c6d9bfab78d5f903 across 29 fraudulent withdrawals in a single transaction. Subsequent movement not detailed in available sources.
Exploit transaction: 0x5ff6dbc33e77fab8dc086bb9ea3c88f1ba81df198d24ec9fc0c5b50fb1a4a17d. Victim pool (Veil_01_ETH, 0.1 ETH denomination, a Tornado Cash fork on Base): 0xd3560ef60dd06e27b699372c3da1b741c80b7d90. Misconfigured Groth16 verifier: 0x1e65c075989189e607ddafa30fa1a0001c376cfd. Attack contract created in the tx: 0x5f68ad46f500949fa7e94971441f279a85cb3354. Recipient: 0x49a7ca88094b59b15eaa28c8c6d9bfab78d5f903. The pool held 2.9 ETH (29 deposits of 0.1 ETH) belonging to legitimate, anonymo

Timeline: On approximately 20 February 2026, an attacker drained the legacy Veil_01_ETH privacy pool on Base (a 0.1 ETH-denomination Tornado Cash fork) by exploiting a fatal misconfiguration in its Groth16 zk-SNARK verifier. The verification key's delta parameter had been left identical to gamma (both pinned to the BN254 G2 generator, the snarkjs Phase 2 default placeholder that should be replaced during a trusted setup ceremony). This collapses the soundness of the pairing check: because gamma2 == delta2, any change to the public inputs can be compensated by a linear change to the proof's C component, so a single valid proof can be 're-bound' to arbitrary public inputs without knowing any witness or having ever deposited. In one transaction (0x5ff6dbc3...4a17d), the attacker deployed a helper contract (0x5f68ad46...b3354) which called the pool's withdraw() function 29 times, each time with a fabricated nullifierHash incrementing from 0xdead0000 to 0xdead001c and a freshly computed C point, withdrawing 0.1 ETH per call for a total of 2.9 ETH to recipient 0x49a7ca88...5f903. The same delta2==gamma2 bug class was reused days later in the larger FoomCash exploit (~$2.26M, late February 2026), which BlockSec Phalcon flagged as a copycat of Veil Cash. Pashov Audit Group (which had audited Veil Cash, though the Verifier was out of scope) publicly acknowledged the incident as 'a small, but real hack.' Detailed root-cause analyses were published by independent researchers (CoinsBench / Evgenii, the DK27ss PoC repo) and by Rekt. Recovery status is not confirmed in available sources.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)