🚨 TheRedVillage.com - Loss $80.7K (2026-09-21)
Network: Polygon
Type: Access Control
On Sep 21 Defimon detected an exploit on The Red Village, an NFT fighting game on Polygon. PolygonTRVRouter.forwardRequest() is public and makes the router call any registered service with any calldata the caller passes. The router holds the "_authorizeUpgrade" role, so the attacker used it to call upgradeTo on the SeasonService UUPS proxy and point it at their own unverified implementation. That implementation contains a delegatecall backdoor gated to the attacker's tx.origin. SeasonService holds the transferERC20In/Out roles on TRVZooKeeper, the contract players approve WETH to for tournaments.
About 13 minutes later, the backdoor used transferERC20In to pull WETH from ~299 player wallets that had approved ZooKeeper, then used transferERC20Out to send ZooKeeper's whole balance, 31.43 WETH, to the attacker. The proceeds were then bridged out via LI.FI. Two weeks later the exploiter received an onchain message to negotiate the bounty.
TX: https://polygonscan.com/tx/0xac0666c534dcad575cdb1fbcbe5b74e8bba418e35f4273933f62167d5143d55d
Drain TX: https://polygonscan.com/tx/0x3730141adea0cd5a64824c0a541c4405256b4054ac54d8c1de65fe6ba210dd35
Attacker: https://polygonscan.com/address/0xa566592cb94475baf5b46ce373a260dfc9d0df3f
Victim: https://polygonscan.com/address/0xc97dcb0492412bfbbf47332f1b1b49e177e8f15c (TRV Router)
Victim: https://polygonscan.com/address/0x426d27190a2ddb87f1c6235f710e159a0a3774d4 (TRVZooKeeper)
@defimon_subscription_bot
Post #3375
454
Defimon Alerts 💌 Onchain message: To the party responsible for this exploit. Our priority is to recover the funds and resolve this matter constructively. We offer a 10% recovery bounty, conditional on returning 77558 DAI, representing 90% of the stolen funds, to 0xBd2…
