Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

NFT Liquidity Platform Gondi Exploited, NFTs Worth $230K Stolen on Ethereum

Ethereum-based NFT lending platform Gondi faces a smart contract exploit that allowed attackers to steal high-value NFTs from multiple users, raising fresh concerns about security risks in NFT lending protocols.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
March 9, 2026
in Security & Hacks
0 0
Gondi Exploited
Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

NFT liquidity marketplace Gondi has suffered a security exploit that resulted in the theft of multiple high-value NFTs worth approximately $230,000 (around 118 ETH). The incident was first flagged by blockchain security firm GoPlus Security and appears to affect users who interacted with the platform’s loan repayment features. The exploit has raised fresh concerns about smart contract vulnerabilities in NFT lending platforms, an area that has grown rapidly within the decentralized finance (DeFi) ecosystem. Early blockchain analysis suggests that attackers were able to exploit a flaw in one of Gondi’s core contracts, enabling unauthorized transfers of NFTs from affected wallets. Security researchers and community members are now closely monitoring the situation as investigations continue.

NFT Liquidity Platform Gondi Exploited
NFT Liquidity Platform Gondi Exploited

Exploit Targets Gondi Smart Contract

According to preliminary findings, the exploit targeted Gondi’s Purchase Bundler smart contract, which is used to manage bundled NFT purchases, sales, and transactions related to lending operations.

The affected contract address is:

0xc10472ac1bf9f2e58ff2c83596b4535334c90814

Attackers reportedly exploited a vulnerability that allowed them to transfer NFTs without authorization, even after certain loans associated with those assets had already been repaid.

Key Addresses Involved

  • Attacker wallet: 0x8D171c74c85CD2Ec9F38143Dd5d8a7c89DF47051
  • Attack contract: 0xe95e3cfC4939D6D98DBDa31AAfE950c3Ee84d73c

Major NFT Collections Affected

Blockchain transaction records show that several high-profile NFT collections were targeted during the exploit.

Notable transactions include:

Transaction 1
Hash: 0x0089f51edf53299ad357229ec4614efc57b3fcd3f395d088f33ce9a9261d2820

  • Transferred 3 SuperRare NFTs from wallet zenVault.eth.

Transaction 2
Hash: 0x83bac5d4b222b97f9734637c072589da648941b8a884ce1a61324dc0449e6a06

  • Drained approximately 78 NFTs across 10 collections, including:
    • Art Blocks (44)
    • Doodles (10)
    • Bored Ape Yacht Club (2, including #1502)
    • KnownOrigin
    • LilPudgys
    • Other smaller collections.

Shortly after the theft, the attacker converted the stolen assets into WETH and moved the funds within minutes, according to on-chain data.

Prominent Wallets Impacted

Several well-known NFT collectors and wallets were reportedly affected by the exploit, including:

  • zenVault.eth
  • roadweb.eth
  • onchainpal.eth
  • NFTLaurent

NFTLaurent later reported losing personal pieces, including a “servant token” created by artist lphaCentauriKid.

Gondi Team Confirms Investigation

A member of Gondi’s product team, BBA (X handle: @ape6743), acknowledged the incident in a post on X.

“It appears there has been an exploit on the Gondi platform that allowed some NFTs to be stolen.
The team is currently investigating the situation and will report back as soon as possible.”

He added that the issue appears to be limited to a specific use case, and stated that assets currently held in custody remain safe.

BBA also confirmed that the affected contract appears to be the Purchase Bundler contract.

As of late afternoon IST on March 9, 2026, the official @gondixyz account had not released a formal statement regarding the exploit. The account’s recent posts continue to focus on platform updates, including loan features and the launch of an Artists Directory.

Security Recommendations for Users

Following the incident, security researchers recommend that Gondi users take the following precautions:

  • Revoke approvals immediately for the affected contract
    0xc10472ac1bf9f2e58ff2c83596b4535334c90814 using tools such as revoke.cash or Etherscan’s approval checker.
  • Pause all activity on the Gondi platform until an official update is released.
  • Monitor wallets closely using blockchain explorers such as Etherscan or DeBank for suspicious activity.
  • Regularly review and revoke unused token approvals when interacting with DeFi and NFT platforms.

Ongoing Investigation

The incident highlights the security risks associated with NFT lending protocols, particularly vulnerabilities linked to residual permissions after loan repayments. The Gondi team has stated that a full investigation report will be released once their analysis is complete.

The exploit also comes at a time when the crypto industry continues to face a series of security incidents across different platforms. In a separate case, a crypto casino platform recently announced a $500,000 bounty after a $4.3 million exploit, highlighting how attackers are increasingly targeting vulnerabilities in blockchain-based platforms.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto HacksEthereum
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

BitMine's Buyback Is Doing More Work Than Its ETH Buy This Week
Market Updates

BitMine’s Buyback Is Doing More Work Than Its ETH Buy This Week

by Ilampirai Arivazhagan
July 27, 2026 - Updated on July 28, 2026

BitMine Immersion Technologies (NYSE: BMNR) added 9,946 ETH over the past week, the second smallest weekly purchase since it started...

Read moreDetails
Drift Protocol Hacker Moves $44M in ETH to Tornado Cash After Three Months

Drift Exploiter Moves $44M in ETH Through Tornado Cash After Three Months of Inactivity

July 24, 2026
Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Unauthorized Memecoin

Hackers Compromise Robinhood CEO Vlad Tenev’s X Account to Promote Fake VLAD Token

July 24, 2026
Three Crypto Exploits Drain Over $35.5 Million in Hours as Verus, AFX, and B² Are Hit

Multiple Bridge Exploits Drain $35 Million Across Bitcoin and Ethereum Networks

July 23, 2026
VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

VerusCoin Ethereum Bridge Exploited for $7.54 Million in Repeat Attack

July 23, 2026
SecondFi Shuts Down Following $2.6 Million ADA Security Breach

SecondFi Shuts Down Following $2.6 Million ADA Security Breach

July 22, 2026
Balance Coin Crashes 99% After $915K Exploit Hits 42DAO Protocol

Balance Coin Crashes 99% After $915K Exploit Hits 42DAO Protocol

July 22, 2026
Next Post
Stablecoin Payments Firm KAST Raises $80 Million in Series A Funding

Stablecoin Payments Firm KAST Raises $80 Million in Series A Funding

Bitmine’s (BMNR) Announces ETH Holdings Reach 4.535M and Total Holdings of $10.3 Billion

Bitmine’s (BMNR) Announces ETH Holdings Reach 4.535M and Total Holdings of $10.3 Billion

Recommended

  • All
  • Crypto News Today
CZ Backs ASEAN Crypto Passporting, But the Philippines’ Own Pilot Still Needed Two Licenses

CZ Backs ASEAN Crypto Passporting, But the Philippines’ Own Pilot Still Needed Two Licenses

July 28, 2026
Circle Becomes Largest U.S. Blockchain Patent Holder After IBM Deal

Circle Claims U.S. Blockchain Patent Lead With IBM Portfolio Acquisition

July 28, 2026
Hong Kong Banks Get Their Quantum Report Card, Months After It Was First Promised

Hong Kong Banks Get Their Quantum Report Card, Months After It Was First Promised

July 28, 2026
Payward Acquires Magic Labs' Wallet Business to Expand B2B Infrastructure

Kraken Parent Payward Acquires Magic Labs’ Embedded Wallet Business

July 27, 2026 - Updated on July 28, 2026
BitMine's Buyback Is Doing More Work Than Its ETH Buy This Week

BitMine’s Buyback Is Doing More Work Than Its ETH Buy This Week

July 27, 2026 - Updated on July 28, 2026
Michael J. Saylor (Bitcoin)

Strategy’s USD Reserve Hits $3.75 Billion as Bitcoin Holdings Stay Flat for a Fourth Week

July 27, 2026
Crypto Token Unlocks This Week: SUI, EIGEN and FF Lead More Than $55 Million in Scheduled Releases

Crypto Token Unlocks This Week: SUI, EIGEN and FF Lead More Than $55 Million in Scheduled Releases

July 27, 2026
Drift Protocol Hacker Moves $44M in ETH to Tornado Cash After Three Months

Drift Exploiter Moves $44M in ETH Through Tornado Cash After Three Months of Inactivity

July 24, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Tether Signs Nairobi Securities Exchange MoU, Third African Continent Expansion Move in July
  • CZ Backs ASEAN Crypto Passporting, But the Philippines’ Own Pilot Still Needed Two Licenses
  • Circle Claims U.S. Blockchain Patent Lead With IBM Portfolio Acquisition

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.