Friday, July 31, 2026

Pepe meme creator’s NFT projects hit for $1 million as contract hijackers mess up collections

Published:

[ad_1]

Projects tied to Pepe meme creator Matt Furie and the NFT studio ChainSaw misplaced roughly $1 million to contract takeover exploits last week, according to on-chain investigator ZachXBT.

On June 27, ZachXBT reported transaction information displaying that the attacker seized management of the “Replicandy” contract at 4:25 a.m. UTC on June 18 by transferring possession to the externally owned tackle 0x9Fca. 

Two hours later, the new proprietor withdrew mint proceeds and, at 5:11 a.m. the next day, reopened the mint, issued recent NFTs, and dumped them into open bids, pushing the ground value to zero.

On June 23, the same tackle took over three further ChainSaw contracts: Peplicator, Hedz, and Zogz. The unhealthy actor then repeated the mint-and-dump cycle. 

ZachXBT estimated the mixed theft at more than $310,000 and linked the funds to three collector addresses: 0xf6a9, 0x7e58, and 0x58f4. He traced a 2.05 ETH fee from 0x9Fca to an alternate deposit that transformed to 5,007.91 USDT and was then moved to MEXC

He subsequently mapped many smaller month-to-month deposits from unrelated projects into the same alternate pockets.

Two GitHub accounts, “devmad119” and “sujitb2114,” checklist wallets that intersect the stolen fund path. 

Both accounts share indicators that ZachXBT related with North Korean IT employees, including Korean language system settings, Astral VPN classes, and Asia-Russia time zones, despite résumés that declare US residency.

Favrr exploit follows the same payroll path

A second incident surfaced on June 25, when the freelance companies token mission Favrr misplaced more than $680,000 following its itemizing on a DEX. On-chain evaluation linked the exploit to the consolidation pockets 0x477, which obtained recurring funds from Favrr payroll addresses 0x1708 and 0x6412. 

Gate.io deposit tackle 0xab7 obtained half of the stolen Favrr tokens, and was beforehand funded by the suspected developer behind “sujitb2114”.

Favrr introduced that it would refund all preliminary decentralized providing individuals, cancel its MEXC itemizing, and provoke a thorough audit of its codebase. The mission added that it will publish a new launch timeline “in the coming weeks” and suggested customers to keep away from buying and selling impostor tokens in the interim.

ZachXBT reported that Favrr’s chief expertise officer, listed as Alex Hong, deleted his LinkedIn profile after the exploit. Attempts to confirm his work historical past with earlier employers had been unsuccessful.

The investigator plans to launch combination knowledge on payroll flows to wallets tied to the same North Korean cluster, contending that primary due diligence checks would have flagged the hires.

The stolen funds from the ChainSaw collections stay idle, while most Favrr proceeds have already handed through Gate.io and several nested companies. 

ZachXBT stated he has not reached the groups because their direct message channels are closed, and official Telegram or Discord rooms do not present contact choices.

The incidents convey renewed consideration to the dangers of “shadow hiring” in crypto projects that outsource improvement through gig-work platforms. 

Investigators proceed to observe the on-chain trails, and affected communities await formal statements from Furie, ChainSaw, and Favrr.

[ad_2]

BlockBuzzed
BlockBuzzedhttps://blockbuzzed.com
Bringing you the latest trends, insights, and updates from the world of blockchain and cryptocurrency, the BlockBuzzed team is passionate about making digital assets accessible and understandable for everyone. Whether breaking news, in-depth guides, or expert analysis, our authors strive to empower readers with timely and accurate information.

Related articles

Recent articles