Blockchain game Munchables, which offers rewards for looking after digital creatures, loses ~$63M in ETH in a hack; the hacker seems to have returned the funds
- Blockchain-based Munchables game confirmed a security incident — Munchables declared all user funds safe later the same day
The apparent return of the ETH and Munchables’ statement that user funds are safe distinguish this episode from incidents that required prolonged operational restrictions. Even so, the breach puts the game’s custody and smart-contract safeguards under immediate scrutiny.
First-order effects
Munchables users avoid an apparent loss of roughly $63M in ETH if the returned funds and the project’s safety assessment hold.
Munchables must account for the breach and demonstrate that the exploited path is closed before users can treat its reward system as secure.
Second-order effects
Players and prospective users are likely to place greater weight on a game’s contract security and asset-handling practices, raising the trust burden for Munchables and comparable blockchain games.
Repeated high-value exploits can make security assurance and recovery readiness a competitive requirement for consumer-facing crypto products, rather than a back-end technical concern.
If such incidents continue, the sector may further separate projects able to preserve user access after a breach from those whose failures force asset freezes or extended disruption.
The trend: Blockchain gaming is part of a broader crypto trend in which consumer adoption increasingly depends on whether protocols can contain security failures without exposing users to lasting losses.
The Munchables developer has shared all private keys involved to assist in recovering the user funds. Specifically, the key which holds $62,535,441.24 USD, the key which holds 73 WETH, and the owner key which contains the rest of the funds.
$97m has been secured in a multisig by Blast core contributors. Took an incredible lift in the background but I'm grateful the ex munchables dev opted to return all funds in the end without any ransom required. @_munchables_ and protocols integrating with it like @juice_finance..…
The fund is currently in a multisig wallet 0x4D2F75F1cF76C8689b4FDdCF4744A22943c60 48C, with the threshold 2/3. Owners are 0xFfE8d74881C29A9942C9D7f7F55aa0d8049C3 04A, 0xe0C5B8341A0453177F5b0Ec2fcEDc57f6E211 2Bc, 0x94103f5554D15F95d9c3A8Fa05A9c79c62eDB D6f
Zach played a big role in stopping a $63m exploit today Just sent a small thank you to zachxbt.eth for his services. If you were on Munchables prior to today I suggest you do the same [image]