Incident case file
Sign in to watchWUSD.fi / GLOVE — Incentive Sybil Abuse on _englove Reward Path
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x88329A09428778F62BC0C8BAac0997864E5a57f8 (exploiter EOA). Wallet created the same day as the exploit; ~50 transactions compressed into one hour, 41 unknown-contract interactions, ~99.79% counterparty concentration (per KaelAi) -- characteristic of disposable exploit infrastructure.
Timeline: On 25 May 2026 at 06:07:59 UTC (Ethereum block 25170426), an attacker exploited the WUSD._englove reward path, which let any fresh msg.sender wrapping at least 100 WUSD while holding fewer than 2 GLOVE receive up to 2 GLOVE via Glove.mintCreditless, with no Sybil resistance. Using EIP-7702 helper contracts and a Morpho USDT flash loan (~81.8M USDT), the attacker ran repeated wrap/unwrap cycles with fresh addresses to harvest GLOVE, then dumped it into the Uniswap V3 GLO-USDC and GLO-USDT pools, extracting about 11,702 USDC and 8,079 USDT (~$200K). The exploiter EOA (0x88329A09...5a57f8) was a freshly created wallet exhibiting classic disposable-exploit behaviour (50 transactions in one hour, 41 unknown-contract interactions, ~99.79% counterparty concentration, per KaelAi). ExVulSec flagged the incident at ~09:54 UTC on 25 May, and PeckShield confirmed at ~13:59 UTC that the attacker had swapped the proceeds for ~98 ETH and Shielded them into Railgun (~$207K), tx 0x98a5bfe6...ae8f70e. The headline loss figure of $200K (SlowMist / ExVulSec) is used; PeckShield's ~$207K cash-out figure is recorded under funds moved. Recovery: 0%.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/25/wusd-fi-glove-incentive-abuse-drains-200k-from-uniswap-v3-pools/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlex.comhttps://x.com/exvulsec/status/2058803971947385330
- Articlex.comhttps://x.com/PeckShieldAlert/status/2058865446984802630
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)