ChainBleedv0.1 · open intel
← back to feed·SOCIAL-ENGINEERING2025-04-27 · 1y ago
Incident · SLOWMIST

QuantMaster

Insider Manipulation
Estimated loss
$100.0K
VERDICT —OUT OF SCOPE
Root cause is social engineering — privileged personnel deceived into authorizing the drain. Contract behaved as written. Defense lives in process controls (multi-party approval, M-of-N signoff windows), not in smart-contract review.
▰ METHOD
SOCIAL ENGINEERING
SOCIAL-ENGINEERING
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

A member of the crypto community previously revealed that "a smart contract of a certain Web3 project was suspected to have been implanted with malicious code by an employee," leading to losses of several hundred thousand dollars. Thomson, a developer of the DeFi trading and asset management project QuantMaster, stated that he was the primary victim of this theft. According to Thomson, the suspect has been largely identified. The GitHub submission records clearly point to a specific employee, and the device used to submit the code is also unique. Cursor retains a complete local AI activity log, which has been reviewed, ruling out the possibility that the malicious code was generated or modified by AI. Attack method (per SlowMist): Insider Manipulation. Reported loss: $100,000.

Primary source
https://x.com/thomsonYang_147/status/1916719524327686385
Sourced from
slowmist
Technical record
chain
protocol
QuantMaster
bug_class
social-engineering
date_occurred
2025-04-27
loss_usd
$100,000
source_id
sm:quantmaster::2025-04-27
Related — same bug class· social-engineering
2026-05-11
1mo ago
SOL
Roaring Kitty X Account → $RKC memecoin pump-dump
X account takeover → coordinated memecoin pump-and-dump on Pump.fun
social-engineering
$2.86M
OUT OF SCOPE
2026-04-01
2mo ago
SOL
Drift Protocol
DPRK-linked Privileged-Access Drain
social-engineering
$286.00M
OUT OF SCOPE
2026-02-23
3mo ago
WLFI
Social Engineering
social-engineering
OUT OF SCOPE
2025-09-01
9mo ago
BSC
OlaXBT
Multisig wallet Social Engineering Exploit
social-engineering
$2.00M
OUT OF SCOPE
2025-07-24
10mo ago
MULTI
WOO X
Social Engineering
social-engineering
$14.00M
OUT OF SCOPE
2025-04-11
1y ago
ETH
Jake Gallen
Social Engineering
social-engineering
$100.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence