logo

Time Token Exploit

ID: 2c6bdf5e-7a81-5f4f-a373-1cb0b0e7a8ce

STIX ID: report--2c6bdf5e-7a81-5f4f-a373-1cb0b0e7a8ce

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2023-12-08

Date Updated: 2026-06-11

...
...

On 7 December an attacker exploited a framework-level integration bug between ERC-2771 Forwarder and a contract using multicall/delegatecall to cause the TIME token contract to burn ~99.9% of a targeted pool's TIME supply and extract ~84.6 ETH (~$188K). The root cause is incorrect calldata handling that truncates the verified req.from value, enabling unauthorized execution and subsequent price manipulation and theft; the issue affects other projects using the same pattern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.