Tools Crypto Exploit Tracker exploit-0148
Exploit record
MUSystem pays deposit bonuses twice, losing about $36,900
- Loss
- $37k
- Attack vector
- Logic Flaw
- Chain
- Ethereum
- Sector
- DeFi
What happened
SlowMist reports that an attacker drained about $36,900 from MUSystem by collecting a first-deposit bonus twice. The contract counted the bonus both in an immediate Ether refund and in the user’s token allocation.
The attacker could then withdraw in the same transaction, with the Ether repayment exceeding the deposit. SlowMist describes repeating the process through 16 fresh addresses. Its three linked transactions share the 30 September 03:27 UTC block; the dollar loss is the researcher’s estimate.
On-chain references
- Incident transactionetherscan.io/tx/0xfe28118e48c64b275b587c90da472fc13b8c3dbed9…
Sources
- Researcher reportx.com/SlowMist_Team/status/2105167166639407447
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 5 October 2026