Malicious Adapter Drains $142k from Enjin Crypto Items Platform
A financial exploit has drained approximately $142,000 from Enjin's Ethereum-based 'Crypto Items' platform. On August 25, an attacker used a malicious adapter to bypass the approval check and transfer 52 unrelated wallet holders' items in one transaction.
The stolen Crypto Items contained 500 ENJ each, totaling around 5.24 million ENJ. The attacker then invoked the melt() function on every item, triggering payouts from Enjin's reserve and draining the funds into their externally owned account.
According to Defimon, a security monitor, the vulnerability stemmed from an unprotected initialize function and storage-layout mismatch in delegate-call adapters, which are typical upgradeable-contract flaws.