Enjin ERC-1155 Crypto Items flaw drained assets from about 52 wallets

Enjin ERC-1155 Crypto Items flaw drained assets from about 52 wallets

N
News Editor
2026-08-27 06:38:50
ChainCatcher reported that Enjin’s ERC-1155 "Crypto Items" let each item route transfers through a dedicated item adapter. An attacker registered and used a malicious transfer adapter to bypass owner approval checks. That allowed the attacker’s vulnerable contract to call transferFrom without approval and pull ENJ-backed items from about 52 unrelated holder wallets. After taking the items, the attacker called melt() on each stolen asset and redeemed the 500 ENJ backing attached to each item from the platform reserve. The report identified the issue as an approval-check bypass tied to the transfer adapter design.

ChainCatcher reported that Enjin’s ERC-1155 "Crypto Items" allowed each item to route transfers through a dedicated item adapter.

An attacker registered and used a malicious transfer adapter, bypassing owner approval checks. That let the attacker’s vulnerable contract use transferFrom without approval to extract ENJ-backed items from about 52 unrelated holder wallets.

The attacker then called melt() on each stolen item, redeeming the 500 ENJ backing for each asset from the platform reserve.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.