Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections

Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections

2025/06/27 11:40
By:

Projects tied to Pepe meme creator Matt Furie and the NFT studio ChainSaw lost roughly $1 million to contract takeover exploits last week, according to on-chain investigator ZachXBT.

On June 27, ZachXBT reported transaction records showing that the attacker seized control of the “Replicandy” contract at 4:25 a.m. UTC on June 18 by transferring ownership to the externally owned address 0x9Fca. 

Two hours later, the new owner withdrew mint proceeds and, at 5:11 a.m. the next day, reopened the mint, issued fresh NFTs, and dumped them into open bids, pushing the floor price to zero.

On June 23, the same address took over three additional ChainSaw contracts: Peplicator, Hedz, and Zogz. The bad actor then repeated the mint-and-dump cycle. 

ZachXBT estimated the combined theft at more than $310,000 and linked the funds to three collector addresses: 0xf6a9, 0x7e58, and 0x58f4. He traced a 2.05 ETH payment from 0x9Fca to an exchange deposit that converted to 5,007.91 USDT and was then moved to MEXC. 

He subsequently mapped many smaller monthly deposits from unrelated projects into the same exchange wallet.

Two GitHub accounts, “devmad119” and “sujitb2114,” list wallets that intersect the stolen fund trail. 

Both accounts share indicators that ZachXBT associated with North Korean IT workers, including Korean language system settings, Astral VPN sessions, and Asia-Russia time zones, despite résumés that claim US residency.

Favrr exploit follows the same payroll path

A second incident surfaced on June 25, when the freelance services token project Favrr lost more than $680,000 following its listing on a DEX. On-chain analysis linked the exploit to the consolidation wallet 0x477, which received recurring payments from Favrr payroll addresses 0x1708 and 0x6412. 

Gate.io deposit address 0xab7 received part of the stolen Favrr tokens, and was previously funded by the suspected developer behind “sujitb2114”.

Favrr announced that it would refund all initial decentralized offering participants, cancel its MEXC listing, and initiate a thorough audit of its codebase. The project added that it will publish a new launch timeline “in the coming weeks” and advised users to avoid trading impostor tokens in the interim.

ZachXBT reported that Favrr’s chief technology officer, listed as Alex Hong, deleted his LinkedIn profile after the exploit. Attempts to verify his work history with previous employers were unsuccessful.

The investigator plans to release aggregate data on payroll flows to wallets tied to the same North Korean cluster, contending that basic due diligence checks would have flagged the hires.

The stolen funds from the ChainSaw collections remain idle, while most Favrr proceeds have already passed through Gate.io and several nested services. 

ZachXBT said he has not reached the teams because their direct message channels are closed, and official Telegram or Discord rooms do not provide contact options.

The incidents bring renewed attention to the risks of “shadow hiring” in crypto projects that outsource development through gig-work platforms. 

Investigators continue to follow the on-chain trails, and affected communities await formal statements from Furie, ChainSaw, and Favrr.

The post Pepe meme creator’s NFT projects hit for $1 million as contract hijackers drain collections appeared first on CryptoSlate

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!