Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

FOOM Club Exploit: $1.8 Million Lost Due to Smart Contract Misconfiguration

FOOM Club Exploit: $1.8M lost due to a smart contract vulnerability. Whitehats race to rescue funds on the Base network

by Saravana Kumar Mahendran
February 26, 2026
in Security & Hacks
0 0
FOOM Club
Share on FacebookShare on Twitter

 A significant security breach has struck the FOOM Club ecosystem, resulting in an exploit of approximately $1.8 million. The attack, which targeted the project’s lottery contract, was triggered by a technical flaw in the Groth16 verifier, leading to a massive drain of digital assets.

The Technical Root Cause

Security analysts at CertiK Alert  identified the primary cause of the exploit as a critical misconfiguration within the Groth16 verifier. Specifically, the vulnerability stemmed from the delta2 == gamma2 setting at the contract address 0xc043865fb4d542e2bc5ed5ed9a2f0939965671a6.

This specific error allowed the exploiter to compute a manipulated ‘pC’ (proof calculation) value, effectively bypassing intended security checks to authorize unauthorized withdrawals from the lottery contract.

Breakdown of the Attack

The breach was first flagged by CertiK Alert  which detected suspicious transactions on the Base network. The timeline and flow of the attack revealed the following details:

  • Attacker Funding: The address responsible for the exploit was initially funded via Binance on the Base network.

  • Malicious Deployment: The attacker deployed a specialized contract to extract assets from “Foom Club: FOOM.Cash”.

  • Asset Drain: A total of 4,588,196,709,531 $FOOM tokens were extracted during the initial phase of the incident.

  • Impacted Accounts: Amidst the exploit, it was noted that the @foomclub account on X had been suspended.

Whitehat Rescue Efforts

Following the detection of the exploit, on-chain data indicated a potential “whitehat rescue” operation. According to Beosin Alert, a significant portion of the funds was transferred to the address whitehat-rescue.eth.

Etherscan transaction records Feb-26-2026 07:39:11 AM UTC confirm multiple high-value transfers from the FOOM Lottery contract to the rescue address. These transfers included batches of several billion $FOOM tokens, valued at hundreds of thousands of dollars each, intended to secure the remaining treasury from further malicious drainage.

Current Status and Market Impact

The total value lost or moved during the event is estimated at $1,822,676.34. While the whitehat intervention may recover a portion of these assets, the incident highlights the persistent risks associated with Zero-Knowledge (ZK) proof configurations in decentralized applications.

Investors are urged to remain cautious as the FOOM team and security firms continue to analyze the extent of the damage. This event serves as a stark reminder that even mathematically “proven” systems like Groth16 can fail if parameters are misconfigured. This incident follows a worrying trend of DeFi vulnerabilities, much like the recent Holdstation security breach where hundreds of thousands in USDT were confirmed stolen due to protocol exploits.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

North Korean AI Hack on Zerion
Security & Hacks

North Korean AI Hack Hits Zerion, $100K Lost in Social Engineering Attack

by Saravana Kumar Mahendran
April 15, 2026

Zerion disclosed a security incident in which a team member’s device was compromised through an AI-enabled social engineering attack linked...

Read moreDetails
Polkadot Bridge Exploit

Polkadot Bridge Exploit Technical Incident Analysis

April 13, 2026
Hyperbridge Exploit

Polkadot Bridge Exploit: 1B Fake DOT Minted on Ethereum

April 13, 2026
SubQuery Staking Contract Exploit

SubQuery Staking Contract Exploit Triggers Withdrawals Pause

April 13, 2026
Weekly Crypto Market Overview April 06 – 12, 2026

Weekly Crypto Market Overview: April 06 – 12, 2026

April 13, 2026
Zerion Web App Shutdown

Zerion Web App Shutdown After Abnormal Activity, Funds Confirmed Safe

April 11, 2026
Aethir Hack

Aethir Hack Contained: Initial $423K Loss Revised to Under $90K After Swift Response

April 10, 2026
Next Post
Ethereum Foundation Launches Strawmap for Future Protocol Development

Ethereum Foundation Launches Strawmap for Future Protocol Development

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • MicroStrategy Buys 34,164 Bitcoin for $2.54 Billion as Accumulation Pace Accelerates
  • Bitcoin “$420B Freeze” Claim Explained: What Developers Actually Proposed
  • Unified Labs partners with Morpho on RWA risk services in Asia

Categories

  • AI × Crypto
  • Data & Dashboards
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.