🚨 Nimiq.com exploited for $50.4K on Polygon (Sep 16, 2026)
Nimiq's swap contracts serve as both the OpenGSN paymaster and the forwarder. Their execute() checks never verifies the user's signature. It relies on the contract's own preRelayedCall to do that. OpenGSN's RelayHub lets any relay choose any paymaster and forwarder.
Exploit contract was detected by Defimon 19 minutes before the attack. The attacker staked 1 POL, registered their EIP-7702 EOA as the relay manager, worker and paymaster (an accept-everything paymaster), and set forwarder = the HTLC handlers. Signature checks were skipped, so forged open() requests "from" a swap-liquidity wallet with unlimited approvals to the handlers opened HTLCs for its entire USDC, USDT0 and USDC.e balance. Each HTLC named the attacker's precomputed CREATE2 contract as recipient and used hashlock sha256(0x01). The exploit tx deploys that contract and redeems all three HTLCs with secret 0x01. About $50.4K was taken and consolidated as USDC.
TX: https://polygonscan.com/tx/0xb2ca76dfbfe571742b4b66465b777ab1e06988a8632be1631bef9654cc64d169
Setup TX: https://polygonscan.com/tx/0xb067efae73637f3564f58af7f6027afc497e81e47624b0048636085c678858c0
Attacker: https://polygonscan.com/address/0x2258491525c21f334c5a2dc22ce55e55023fc45d
Victim: https://polygonscan.com/address/0x0cfd862be942846cebad797d7c1bc6e47714959b
Victim: https://polygonscan.com/address/0xf615bd7ea00c4cc7f39faad0895db5f40891359f
Drained wallet: https://polygonscan.com/address/0x24cb173ae221aea93369f34bdcf0ddb35b436773
X: https://x.com/nimiq
@defimon_subscription_bot
Post #3310
835

- ❤ 3
- 🤣 1