Normie Incident Analysis
ID: 5baf571f-79d2-56ac-9af6-8e97f2db1caf
STIX ID: report--5baf571f-79d2-56ac-9af6-8e97f2db1caf
Feed Name: CertiK Blog
On 26 May 2024 a flash-loan exploit of the NORMIE token on Base abused a vulnerability that added any address receiving the same number of tokens as the deployer to a premarket_user list, enabling contract self-minting and repeated swapAndLiquify sells that inflated supply and crashed the token price by ~99%; the attacker extracted ~224 WETH (~$881k), moved funds across bridges, and is allegedly negotiating to return 90% contingent on developer actions. The report includes the attack flow, contract and exploiter addresses, example transaction links, tracing of initial funding and post-exploit movement, and a remediation lesson recommending audits for forked contracts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
