Namada Protocol — MASP IBC Transfer Logic Exploit (June 19 2026)
Summary
On June 19, 2026, Namada Protocol's Multi-Asset Shielded Pool (MASP) was drained of approximately $600,000 in IBC-bridged assets including ATOM, USDC, OSMO, TIA, and NYM via an IBC Transfer Logic Exploit. The attack went undetected for a material period because a stale chain indexer continued displaying the drained balances as available, while live RPC queries showed zero; the discrepancy was first identified by independent security researchers at F12. Namada confirmed the exploit and issued an appeal to the responsible party to contact them, but as of the investigation date had not disclosed the specific vulnerability, recovery status, or a comprehensive postmortem.
Connected Entities
1 entities · 10 linked investigationsTimeline(5 events)
2024-12-03
Namada Protocol mainnet launched via a community-coordinated genesis event involving over 180 independent validators.
CoinTelegraph / Namada Official2026-06-18
Alleged beginning of exploit window. The attacker began draining IBC-bridged assets from Namada's MASP via IBC Transfer Logic Exploit, according to CryptoTimes reporting citing F12.
CryptoTimes2026-06-19
Approximately $600,000 in assets (ATOM, USDC, OSMO, TIA, NYM and others) confirmed drained from Namada's MASP. Stale indexer continued showing balances intact; live RPC queries showed zero. Independent security researchers at F12 detected the discrepancy by cross-referencing data sources. Attacker IBC-transferred approximately 228,517 ATOM to address cosmos1zw9weagzm2w4ud6w3ql7m7rvzpxhvkpt8kk4ff, which rapidly emptied further via IBC sends.
CryptoTimes / SlowMist Hacked2026-06-20
CryptoTimes published detailed reporting on the MASP drain, including the stale indexer masking mechanism and F12's on-chain findings. DefiLlama recorded the event in its hacks database as a $600,000 Protocol Logic exploit.
CryptoTimes2026-06-21
Namada team confirmed the exploit publicly, stating: 'There's been an exploit in the Namada protocol. We are investigating the issue and are involving the relevant parties.' Team appealed to 'white hat hacker' to make contact. CoinTrust reported investigation ongoing; no recovery timeline or specific vulnerability disclosure made.
CoinTrustDecision Log
- hash: GxHey7HYPbH9286KcqbZWdx4GWMoUXqxWH5km3o6RE1q
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 6/21/2026, 12:19:07 PM
last updated: 6/21/2026, 12:19:15 PM
avoid.net — verified advice for a post-truth world