Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Old Royalties Contract on Polygon Attacked, $261,200 Lost

An attacker drained funds from a legacy royalties contract tied to the music NFT platform Royal by manipulating its internal ownership tracking.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 24, 2026
in Security & Hacks
0 0
Royal Royalties Contract Exploited on Polygon for $261,200

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A legacy royalties contract linked to the music NFT platform Royal on Polygon was exploited on June 23, 2026, around 16:27 UTC, resulting in the loss of approximately $261,200 in USDC. The attack targeted an older smart contract that had been used for distributing royalties through tokenized music assets, known as Limited Digital Assets (LDAs).

According to CertiK, the incident stemmed from flawed settlement logic that allowed the attacker to stack reward records and claim roughly 100 times their actual share. The attacker took advantage of a vulnerability in the contract’s internal accounting system, using a flash loan and a series of carefully crafted zero-value transfers to manipulate ownership balances. Monitoring services flagged suspicious activity shortly after the transaction.

#CertiKInsight 🚨

We have seen a $263K exploit on the Royalties contract at 0xfE16Ee78828672e86cf8E42d8A5119AB79877EC7 on Polygon.

Through 100 zero-value transfers, the attacker exploited flawed settlement logic to stack reward records and claim 100X reward.

Stay Vigilant! pic.twitter.com/Jjt2yNwZUc

— CertiK Alert (@CertiKAlert) June 24, 2026

The affected Royalties contract at 0xfe16ee…77ec7 acted as a proxy for royalty distributions. Its implementation at 0x1e05…c9074 contained custom accounting logic for LDA tiers. The attacker first borrowed around 2,638 USDC through a flash loan. They then carried out multiple zero-value transfers of the same asset tier. This created an inflated ownership record in the contract without changing the actual token balances. Using this artificial position, the attacker deposited funds and claimed a much larger share of the royalty pool, receiving about 263,809 USDC.

After repaying the flash loan, the net profit came to roughly $261,200. The main attacker address was 0xbd82…bd56, with a helper contract at 0x7fd7…ca52. Royal has not yet released an official statement. It is unclear whether the exploited contract remains part of active operations or represents deprecated infrastructure. Royal previously gained attention for enabling tokenized music ownership on Polygon, where fans could hold fractional song interests and receive streaming royalties through LDAs.

The event fits a recurring pattern of issues involving older or under-maintained contracts on Polygon. Security incidents have also been spreading across NFT-focused platforms this year. Earlier in June, NFT liquidity platform Gondi lost more than $230,000 worth of NFTs in an exploit that once again highlighted weaknesses in specialized digital asset protocols.

Legacy code in DeFi remains a persistent challenge. The latest breach comes during an already difficult year for crypto security, with industry losses from hacks and exploits surpassing $84 million in May as attackers continued to target weaknesses in smart contracts and protocol infrastructure. Many projects use proxy patterns for upgradability, yet abandoned or lightly maintained implementations can become targets when economic conditions make exploitation profitable, especially in royalty and reward systems. This highlights the risks of custom accounting logic in NFT/royalty contracts that doesn’t properly validate transfer amounts.

Developers have faced multiple reminders of these risks in recent weeks, including the exploit of Echo Protocol on Monad, where an attacker minted fake eBTC and stole more than $822,000 from the platform. The attack stayed isolated to this specific contract with no reported spillover to other parts of the Royal ecosystem. No immediate price movements in related assets were observed. Users holding positions in older royalty contracts on Polygon are reviewing their exposure.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto HacksNFT

Related Posts

SecondFi Wallet Vulnerability Drains Millions in Cardano Assets
Security & Hacks

SecondFi Wallet Vulnerability Drains Millions in Cardano Assets

by Saravana Kumar Mahendran
June 24, 2026

SecondFi, the Cardano based self-custody wallet and neofinance platform formerly known as Yoroi, disclosed a security vulnerability in its web...

Read moreDetails
JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

June 22, 2026
Taiko Bridge Exploit

Taiko Bridge Exploit Drains $1.7 Million in Chain State Verification Breach

June 22, 2026
Axelar Network Disables Secret Network IBC Bridge Following $4.67 Million Exploit

Axelar Network Disables Secret Network IBC Bridge Following $4.67 Million Exploit

June 20, 2026
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026
RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

June 17, 2026
Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

June 16, 2026
Next Post
Cboe Launches Cboe Predicts With New S&P 500 Event Contracts Ahead of Q2 2026 Rollout

Cboe Launches Cboe Predicts With New S&P 500 Event Contracts

Recommended

  • All
  • News
Franklin Templeton Completes 250 Digital Acquisition, Launches Franklin Crypto Division

Franklin Templeton Completes 250 Digital Acquisition, Launches Franklin Crypto Division

June 24, 2026
Allium Raises $40M as Demand Grows for Institutional Blockchain Data Services

Allium Raises $40M as Demand Grows for Institutional Blockchain Data Services

June 24, 2026
Cboe Launches Cboe Predicts With New S&P 500 Event Contracts Ahead of Q2 2026 Rollout

Cboe Launches Cboe Predicts With New S&P 500 Event Contracts

June 24, 2026
Royal Royalties Contract Exploited on Polygon for $261,200

Old Royalties Contract on Polygon Attacked, $261,200 Lost

June 24, 2026
Franklin Templeton Completes 250 Digital Acquisition, Launches Franklin Crypto Division

Franklin Templeton Completes 250 Digital Acquisition, Launches Franklin Crypto Division

June 24, 2026
Allium Raises $40M as Demand Grows for Institutional Blockchain Data Services

Allium Raises $40M as Demand Grows for Institutional Blockchain Data Services

June 24, 2026
Smart Contract Is Verified on Etherscan

How to Check if a Smart Contract Is Verified on Etherscan: A Beginner’s Guide

June 24, 2026
Cboe Launches Cboe Predicts With New S&P 500 Event Contracts Ahead of Q2 2026 Rollout

Cboe Launches Cboe Predicts With New S&P 500 Event Contracts

June 24, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Franklin Templeton Completes 250 Digital Acquisition, Launches Franklin Crypto Division
  • Allium Raises $40M as Demand Grows for Institutional Blockchain Data Services
  • How to Check if a Smart Contract Is Verified on Etherscan: A Beginner’s Guide

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.