Incident case file
Sign in to watchWealthManagementV2 Owner Privilege Hijack — 26,414 USDT Loss
Incident date Sep 7, 2026Last updated Sep 24, 2026
0 views
ContainedBNB ChainLeaked private key / owner privilege transferCluster: WMV2-BNB-2026-09
Estimated loss
$26.4K
Affected users
1
Group joining is coming soon.
Investigation
80%
Facts and investigation
Ledger
Attacker
0xe439422afdd247503f75b4143c4a973eced04a36
Funds moved to
26,414 USDT extracted directly from the vulnerable contract following the unauthorized ownership transfer.
Linked
Attacker EOA: 0xe439422afdd247503f75b4143c4a973eced04a36.
Chronology
1 beatOn September 8, 2026, an attacker on BNB Chain gained unauthorized control of WealthManagementV2's owner privileges, most likely via a leaked private key. Once in control, the attacker immediately called updatePlanConfig to set malicious parameters — period=0 and an interestMultiplier/unlockMultiplier of 528,300,000 — without any timelock or bounds check, which allowed inflated interest to be minted and claimed. The attacker extracted 26,414 USDT from the contract before the exploit was flagged.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)