Blockchain game Munchables, which offers rewards for looking after digital creatures, loses ~$63M in ETH in a hack; the hacker seems to have returned the funds
BloombergRyan Weeks
Context & Ripple Effects
Munchables follows a run of security failures across crypto gaming, including the PlayDapp token-minting exploit and VulcanForge wallet compromise. The apparent return of funds distinguishes this case from a simple realized loss, but does not erase the underlying exploit risk.
The incident also sits alongside major DeFi thefts such as the Wormhole bridge hack, where operators had to contain the immediate fallout after funds were taken. For game platforms that hold or route valuable crypto assets, security is therefore part of the product proposition, not merely back-office infrastructure.
First-order effects
Munchables and its users avoid the immediate financial shortfall if the returned ETH is fully recovered, while the platform still must establish how the exploit occurred and whether remaining assets are safe.
The event puts the game’s reward and custody mechanisms under scrutiny, potentially disrupting user confidence even without a permanent loss.
Second-order effects
Other blockchain-game operators face renewed pressure to review smart-contract permissions, wallet controls, and incident-response plans, particularly where game rewards are tied to liquid tokens.
A returned haul may limit direct losses, but security reviews, monitoring, and user-reassurance efforts can raise operating costs and slow launches or feature changes across the segment.
Third-order effects
Repeated exploits in blockchain gaming could shift competition toward platforms able to demonstrate stronger custody design and transparent security practices, rather than reward mechanics alone.
If attacks continue to target tokenized game economies, the sector may increasingly treat recoverability and risk controls as prerequisites for mainstream user trust.
The trend: Blockchain gaming is being tested as financial infrastructure: tokenized rewards make security failures immediately consequential for both players and platform credibility.
$97m has been secured in a multisig by Blast core contributors. Took an incredible lift in the background but I'm grateful the ex munchables dev opted to return all funds in the end without any ransom required. @_munchables_ and protocols integrating with it like @juice_finance..…
The Munchables developer has shared all private keys involved to assist in recovering the user funds. Specifically, the key which holds $62,535,441.24 USD, the key which holds 73 WETH, and the owner key which contains the rest of the funds.
The fund is currently in a multisig wallet 0x4D2F75F1cF76C8689b4FDdCF4744A22943c60 48C, with the threshold 2/3. Owners are 0xFfE8d74881C29A9942C9D7f7F55aa0d8049C3 04A, 0xe0C5B8341A0453177F5b0Ec2fcEDc57f6E211 2Bc, 0x94103f5554D15F95d9c3A8Fa05A9c79c62eDB D6f
Zach played a big role in stopping a $63m exploit today Just sent a small thank you to zachxbt.eth for his services. If you were on Munchables prior to today I suggest you do the same [image]