← Radar

Incident case file

Sign in to watch

WealthManagementV2 Owner Privilege Hijack — 26,414 USDT Loss

Incident date Sep 7, 2026Last updated Sep 24, 2026

0 views

ContainedBNB ChainLeaked private key / owner privilege transferCluster: WMV2-BNB-2026-09

Estimated loss

$26.4K

Affected users

1
Group joining is coming soon.

Investigation

80%

Facts and investigation

Ledger

Attacker

0xe439422afdd247503f75b4143c4a973eced04a36

Funds moved to

26,414 USDT extracted directly from the vulnerable contract following the unauthorized ownership transfer.

Linked

Attacker EOA: 0xe439422afdd247503f75b4143c4a973eced04a36.

Chronology

1 beat
  1. On September 8, 2026, an attacker on BNB Chain gained unauthorized control of WealthManagementV2's owner privileges, most likely via a leaked private key. Once in control, the attacker immediately called updatePlanConfig to set malicious parameters — period=0 and an interestMultiplier/unlockMultiplier of 528,300,000 — without any timelock or bounds check, which allowed inflated interest to be minted and claimed. The attacker extracted 26,414 USDT from the contract before the exploit was flagged.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)