VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
The QI Vesting contract on the streaming digital asset protocol Superfluid has been exploited by an attacker by passing in incorrect call data. This vulnerability allows the attacker to transfer funds from Superfluid user wallets to Polygon and exchange them for ETH. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 13,000,000.
Sourced from
slowmist
Technical record
- chain
- polygon
- protocol
- Superfluid
- bug_class
- logic
- date_occurred
- 2022-02-08
- loss_usd
- $13,000,000
- source_id
- sm:superfluid::2022-02-08
Related — same bug class· logic