Following the loss and recovery of nearly $63 million from a rogue in-house developer, Munchables has devised a new strategy to avoid making the same mistake again. The Ethereum-based NFT game Munchables lost over 17,400 Ether to a hacker, who was later identified as a Munchables developer. Soon after the developer decided to return the stolen funds without asking for a ransom, the situation de-escalated.
Munchables to restart with a bang
In spite of narrowly escaping what could have been a catastrophic loss, Munchables has announced that it is implementing a number of changes to “upgrade the security of the project’s funds and smart contracts.”
In order to ensure the safe return of users’ funds, one of the strategies involves onboarding investment firm Manifold Trading, market maker Selini Capital and blockchain investigator ZachXBT as new multisig signers.
A re-audit and upgrade to new contracts will also be undertaken by developers from Manifold Trading and Selini Capital, and Munchables will be overseeing the hiring process. In preparation for Munchables’ relaunch, Ethereum infrastructure firm Nethermind will further audit the refreshed contracts.
Gamers who return to the game after its relaunch will receive higher rewards. Besides providing financial help, the platform has pledged to assist recovery entities. “Finally, we will send ETH and future MUNCH donations to those who were involved in the recovery process of keeping our users safe.”
Users were also warned not to interact with websites to request a refund, as the company will send refunds directly to their wallets. According to blockchain security firm PeckShield, nearly $100 million in digital assets were stolen in March.
Over 30 hacking incidents occurred in the crypto ecosystem in the last month, resulting in the loss of $187 million in funds. The good news is that 52.8% of the hacked funds were returned.
Munchables is one of the top five security incidents in terms of value lost. Also on the list were the Curio hack, the Prisma Finance incident, the NFPrompt hack and the WOOFi exploit.
What had happened?
Blockchain analyst ZachXBT revealed the wallet address of the alleged attacker five days ago, revealing a substantial balance of $62.45 million in Ether.
DeBank data showed the exploiter engaged with the Munchables protocol shortly before it was announced, extracting 17,413 ETH. Later, the exploiter’s wallet address transferred $10,700 worth of ETH through the Orbiter Bridge, converting Blast ETH back into native ETH.
ZachXBT says Munchables hired a North Korean developer under the alias “Werewolves0943” for the exploit.
In response to the incident, Munchables addressed the situation. Users were reassured through an X post, “We’ve allocated a compensatory treasury pool for all users who had ETH deposits to reclaim their funds.” Users were directed to a link to confirm their eligibility. The post was later unavailable.
