Yuga Labs just pulled off a $500,000 cryptocurrency heist – against these hackers


Authoritative editorial Content, reviewed by leading industry experts and seasoned editors. Advertisement disclosure

Yuga Labs, the company behind Bored Ape Yacht Club and CryptoPunks, completed a secret operation on June 8 to rescue 68 top-tier NFTs — worth more than $500,000 — from an active exploit targeting the Flooring Protocol, deploying its own funds and acting before additional attackers could drain assets that included some of the most valuable tokens in NFT history.

Yuga Labs CEO Michael Figge (@mfigge) Announce The successful operation on “We have just completed a whitewash on an exploit discovered in the Flooring Protocol,” Vig wrote, noting that Yuga Labs VP of Blockchain 0xQuit (@0xQuit) led the on-chain recovery efforts.

The operation was funded through GrailsOTC, Yuga Labs’ OTC trading desk — which Fiji said “quietly instructed” to address the capital and NFTs needed to withdraw vulnerable assets from the protocol before additional bad actors can act on the same vulnerability. The company plans to return all 68 NFTs to their original owners once a technical fix is ​​deployed and verified.

How does crypto exploit work?

attack mechanisms, He explained In a technical thread by 0xQuit on X, he reveals a complex vulnerability embedded in the Flooring Protocol’s core accounting logic. A malicious actor turned a dust amount of WETH — a negligible amount — into a near-infinite fpToken balance by exploiting an edge case in how the protocol handles token ownership records. The attacker then used the bloated pool to deplete floor pools, with a subsequent opportunist collecting the now-depleted pool tokens and replacing them with underlying NFTs.

The deeper vulnerability, according to the 0xQuit post, came from packaged ownership and indexing logic — a technical design choice where a malicious token ID could make ownership checks pass while final accounting records a completely different result, creating what he described as “fake ownership.” The unverified balance update resulted in an account overflow, giving the attacker much more credit than he was legally entitled to. Once this bloated balance exists, token prices can be pushed to near zero and liquidity extracted from the pool at will.

After reviewing the initial attack path, the Yuga Labs team identified a second, broader vulnerability that exposed additional NFTs that had not yet been addressed by the original attacker. This discovery triggered an emergency Whitehat operation – where the team moved to divest all vulnerable assets before another actor could independently find and exploit the same second path.

Ethereum ETH ETHUSD ETHUSD_2026-06-08_17-12-22

ETH's price records some upside on low timeframes as seen on the daily chart. Source: ETHUSD on Tradingview

The protocol behind the incident

Floor Protocol Engineer, @0xFreeLunch, I confess On Despite multiple security reviews, the flaw was not discovered, according to his post. The recognition is notable: gas optimization swaps that appear safe in isolation can create exploitable surface area when token IDs fall outside expected ranges.

Flooring Protocol had already been terminating its consumer-facing NFT services since September 2025 – the platform advised FPv2 token holders to redeem assets and exit partial positions before October of that year. However, its smart contracts remained alive with user assets inside them, creating exactly the kind of legacy exposure that attackers are increasingly targeting in legacy DeFi infrastructure.

0xQuit on CryptoPunks — two of which are among the rescued assets — currently carry a floor price of about 32.7 ETH, or roughly $54,612 per token, while BAYC NFTs are at about 9.16 ETH, according to CoinGecko data.

This development represents a pivotal and unusual moment for the emerging sector’s approach to DeFi security. A leading NFT company deploying its balance sheet to rescue third-party assets from active exploitation — recklessly, quickly, and cheaply — is a form of ecosystem responsibility rarely seen in the space. The question the industry will now ask is how many other legacy protocols still carry similar vulnerabilities in their legacy contracts, waiting for an attacker to find the second path before anyone else.

Cover image by Grok, ETHUSD chart by Tradingview

Editing process Bitcoinist focuses on providing well-researched, accurate, and unbiased content. We adhere to strict sourcing standards, and every page is carefully reviewed by our team of senior technology experts and experienced editors. This process ensures the integrity, relevance, and value of our content to our readers.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *