ChainBleedv0.1 · open intel
← back to feed·FLASHLOAN2026-04-15 · 1mo ago
Incident · SLOWMIST

LootBot AI

Contract Vulnerability
Estimated loss
$9.6K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
FLASHLOAN
FLASHLOANBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

LootBot AI’s xLoot NFT Staking contract was exploited via a Logic Error (Duplicate NFT ID in Redemption). The redeem() function did not validate duplicate token IDs in the input array. The _redeemable() logic accumulated ETH rewards per epoch for each ID without checking for duplicates, and the nextRedeem mapping was only updated after payout. The attacker flash-loaned 2.1 ETH, triggered a new epoch, called redeem() with 7 NFT IDs each duplicated 155 times, draining ~6.21 ETH. After repaying the flash loan, net profit was ~4.1 ETH ($9,600). The project appears largely abandoned (last official X activity in 2025). Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 9,600.

Primary source
https://x.com/DefimonAlerts/status/2044709964091187660
Sourced from
slowmist
Technical record
chain
protocol
LootBot AI
bug_class
flashloan
date_occurred
2026-04-15
loss_usd
$9,600
source_id
sm:lootbot-ai::2026-04-15
Related — same bug class· flashloan
2026-05-11
1mo ago
POLY
Ink Finance
Contract Vulnerability
flashloan
$140.0K
UNRATED
2026-05-04
1mo ago
ETH
SmartCredit
Flashloan Exploit
flashloan
$72.0K
UNRATED
2026-05-04
1mo ago
SmartCredit
Flash Loan Exploit
flashloan
$72.0K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Flashloan Exploit
flashloan
$228.0K
UNRATED
2026-04-28
1mo ago
JUDAO
Exploit
flashloan
$228.0K
UNRATED
2026-04-14
1mo ago
BSC
MONA
Deferred LP Burn Exploit
flashloan
$61.0K
UNRATED
ChainBleed — live web3 threat intelligence