{"investigation":{"slug":"munchables","entity_name":"Munchables","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Munchables is a Blast-chain NFT game that suffered a $62.5 million exploit on March 26, 2024, when a contractor later attributed to North Korea exploited a backdoor they had embedded in the project's upgradeable smart contracts before launch. The developer surrendered private keys and the full sum was recovered within approximately 24 hours, but the incident exposed fundamental failures in contractor due diligence and smart contract architecture.","sections":[{"content":"Munchables is an NFT-based play-to-earn game deployed on Blast, an Ethereum layer-2 network developed by the team behind Blur. The game allowed users to lock ETH into smart contracts in exchange for in-game rewards and points within the Blast ecosystem. Like many early Blast projects, Munchables attracted significant total value locked (TVL) as the network offered native ETH yield, making its lock contracts a high-value target. The project's development team included contractors hired pseudonymously, a common but high-risk practice in Web3 development.","heading":"Background","sources":[{"url":"https://www.theblock.co/post/284883/web3-gaming-platform-munchables-loses-62-5-million-in-exploit-zachxbt","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/nft-game-munchables-blast-exploited-62-million","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain investigator ZachXBT identified four GitHub accounts — NelsonMurua913, Werewolves0493, BrightDragon0719, and Super1114 — believed to represent a single individual, or a coordinated cell, linked to North Korea. These accounts had mutually endorsed one another for the Munchables developer role and reportedly transferred payments to the same two exchange deposit addresses, suggesting coordination. The individual or group was hired as a contractor to develop Munchables' smart contracts. Before the contracts were finalized and deployed, the developer allegedly manipulated storage slots in the upgradeable proxy contract to assign themselves a fraudulent balance of 1,000,000 ETH. This manipulation was preserved through subsequent contract upgrades because storage slot values are not reset when proxy implementation addresses change. On March 21, 2024, the smart contract was upgraded to an unverified implementation address, a move now understood to be part of the attacker's preparation. The Pixecraft Studios CEO later noted publicly that the same developer had been hired on a trial basis in 2022 and was described as 'sketchy' before being let go within a month, suggesting warning signs were available but not acted upon by Munchables. North Korean IT worker infiltration of crypto projects has been documented extensively by the UN Security Council and the U.S. Department of Justice, with DPRK-linked actors estimated to have stolen approximately $3 billion in cryptocurrency since 2017.","heading":"The North Korean Developer Backdoor","sources":[{"url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","name":"","type":"other","credibility":3},{"url":"https://rekt.news/munchables-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/analysts-believe-munchables-usd63m-exploit-was-internally-engineered","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"At approximately 9:33 pm UTC on March 26, 2024, Munchables announced on X (formerly Twitter) that it had been compromised and was tracking the exploiter's movements. The attacker withdrew approximately 17,413 ETH — valued at roughly $62.5 million at the time — from the lock contract by calling the withdrawal function against the fraudulently pre-assigned balance of 1,000,000 ETH that had been embedded in storage slots prior to launch. Because the withdrawals passed the contract's internal balance checks (the attacker's stored balance exceeded the withdrawal amount), no on-chain guardrail triggered. The exploit required no flash loan, no external oracle manipulation, and no complex call chain — the backdoor had been planted months in advance and the attacker simply waited for TVL to reach a target threshold. Third-party Blast bridges were temporarily disabled in the immediate aftermath. Only $6,220 worth of ETH was actually moved off-chain by the attacker via a MEXC deposit address before the funds were frozen and negotiations began.","heading":"The $62.5M Drain","sources":[{"url":"https://www.theblock.co/post/284883/web3-gaming-platform-munchables-loses-62-5-million-in-exploit-zachxbt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","name":"","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/third-party-blast-bridges-disabled-after-munchables-loses-62-million-in-exploit/","name":"","type":"other","credibility":3},{"url":"https://rekt.news/munchables-rekt","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Within approximately 11 minutes of ZachXBT publicly identifying the attacker's address and alleged identity, the responsible developer agreed to return the funds without conditions or ransom demands. The developer surrendered all relevant private keys, including the main owner key, granting access to 17,413 ETH and 73 WETH. Blast founder Pacman confirmed on March 27 that the recovered assets — totaling approximately $97 million when including broader Blast contributor holdings — had been secured in a multisig wallet controlled by Blast core contributors. Pacman publicly credited ZachXBT and security researcher samczsun for their behind-the-scenes assistance. A community discussion about rolling back the Blast chain to reverse the exploit was raised but ultimately not pursued, given that the funds had already been recovered through private key surrender. The recovery was considered near-complete, with only the $6,220 withdrawn to the MEXC address unrecovered. Munchables subsequently indicated plans to relaunch the project.","heading":"Funds Returned","sources":[{"url":"https://cryptoslate.com/munchables-recovers-62-5-million-in-user-funds-after-exploit-linked-to-north-korean-hacker/","name":"","type":"other","credibility":3},{"url":"https://decrypt.co/223644/blast-nft-game-munchables-recovers-62-million-exploit","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/zachxbt-onboarded-custodian-return-funds-defi-exploit","name":"","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/news-in-crypto/observers:munchables-will-re-release-after-62m-hack-but-rollback-security-issues-linger","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Munchables incident is classified as a critical insider threat event and supply chain attack. Several structural risk factors are present. First, contractor due diligence failed: the project hired a developer — later attributed to a North Korean-linked actor — without adequate identity verification, despite available warning signals from prior employers. Second, smart contract architecture was insufficiently secured: the proxy contract's upgradeability was controlled by a developer-owned deployer address rather than a project-controlled multisig or timelock, granting a single contractor full unilateral upgrade authority. Third, no pre-launch storage slot audit was conducted that would have detected the fraudulently assigned 1,000,000 ETH balance. Fourth, the speed of recovery — while positive for users — was partly dependent on the attacker voluntarily cooperating rather than on any technical safeguard, meaning the outcome could have been catastrophically different. The incident is widely cited as a textbook example of the North Korean IT worker infiltration playbook and has prompted broader industry discussion about contractor identity verification, multisig deployment controls, and pre-launch storage audits for upgradeable contracts. No criminal charges or regulatory actions against Munchables itself have been publicly reported as of May 2026. The low trust score reflects the severity of the insider compromise, the demonstrated absence of adequate pre-launch security controls, and the inherent risk of re-engaging with a project that suffered this class of failure.","heading":"Risk Assessment","sources":[{"url":"https://www.coindesk.com/opinion/2024/03/27/the-munchables-hack-is-way-worse-than-it-seems","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","name":"","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/29526952/","name":"","type":"other","credibility":3},{"url":"https://github.com/tayvano/lazarus-bluenoroff-research/blob/main/hacks-and-thefts/munchables.md","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022","event":"A developer later linked to the Munchables exploit was briefly hired by Pixecraft Studios, described as 'sketchy,' and let go within a month.","source":"","date_original":"2022-01-01"},{"date":"2024-03-21","event":"The Munchables Lock smart contract was upgraded to an unverified implementation address, later identified as part of the attacker's preparation.","source":""},{"date":"2024-03-26","event":"The exploit was executed: approximately 17,413 ETH (~$62.5M) was withdrawn by the rogue developer using a pre-planted fraudulent 1,000,000 ETH balance in storage slots.","source":""},{"date":"2024-03-26","event":"Munchables announced the breach on X at approximately 9:33 pm UTC and stated it was tracking the exploiter.","source":""},{"date":"2024-03-26","event":"ZachXBT identified the attacker's address and four GitHub accounts (NelsonMurua913, Werewolves0493, BrightDragon0719, Super1114) believed to be North Korean-linked.","source":""},{"date":"2024-03-26","event":"Within approximately 11 minutes of ZachXBT's public identification, the developer agreed to return all funds and surrendered private keys.","source":""},{"date":"2024-03-27","event":"Blast founder Pacman confirmed that the recovered assets had been secured in a multisig controlled by Blast core contributors.","source":""},{"date":"2024-03-27","event":"Munchables announced full fund recovery; community rollback proposals for the Blast chain were not pursued.","source":""}],"sources_used":[{"url":"https://www.theblock.co/post/284883/web3-gaming-platform-munchables-loses-62-5-million-in-exploit-zachxbt","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/nft-game-munchables-blast-exploited-62-million","name":"","type":"other","archive_url":"http://web.archive.org/web/20260427094233/https://cointelegraph.com/news/nft-game-munchables-blast-exploited-62-million","credibility":3,"archive_timestamp":"2026-04-27T09:42:33+00:00"},{"url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","name":"","type":"other","archive_url":"http://web.archive.org/web/20251228044332/https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","credibility":3,"archive_timestamp":"2025-12-28T04:43:32+00:00"},{"url":"https://rekt.news/munchables-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260607071655/https://rekt.news/munchables-rekt","credibility":3,"archive_timestamp":"2026-06-07T07:16:55+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260317025604/https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","credibility":3,"archive_timestamp":"2026-03-17T02:56:04+00:00"},{"url":"https://thedefiant.io/news/defi/analysts-believe-munchables-usd63m-exploit-was-internally-engineered","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://unchainedcrypto.com/third-party-blast-bridges-disabled-after-munchables-loses-62-million-in-exploit/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptoslate.com/munchables-recovers-62-5-million-in-user-funds-after-exploit-linked-to-north-korean-hacker/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260413150611/https://cryptoslate.com/munchables-recovers-62-5-million-in-user-funds-after-exploit-linked-to-north-korean-hacker/","credibility":3,"archive_timestamp":"2026-04-13T15:06:11+00:00"},{"url":"https://decrypt.co/223644/blast-nft-game-munchables-recovers-62-million-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260607202326/https://decrypt.co/223644/blast-nft-game-munchables-recovers-62-million-exploit","credibility":3,"archive_timestamp":"2026-06-07T20:23:26+00:00"},{"url":"https://cointelegraph.com/news/zachxbt-onboarded-custodian-return-funds-defi-exploit","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptodaily.co.uk/news-in-crypto/observers:munchables-will-re-release-after-62m-hack-but-rollback-security-issues-linger","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.coindesk.com/opinion/2024/03/27/the-munchables-hack-is-way-worse-than-it-seems","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptonews.net/news/security/29526952/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829235300/https://cryptonews.net/news/security/29526952/","credibility":3,"archive_timestamp":"2026-08-29T23:53:00+00:00"},{"url":"https://github.com/tayvano/lazarus-bluenoroff-research/blob/main/hacks-and-thefts/munchables.md","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830001015/https://github.com/tayvano/lazarus-bluenoroff-research/blob/main/hacks-and-thefts/munchables.md","credibility":3,"archive_timestamp":"2026-08-30T00:10:15+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:33.933986+00:00","updated_at":"2026-08-30T01:16:28.03845+00:00"}}