How a Planted Developer Nearly Walked Off With $62.5M From Munchables — Until ZachXBT Stepped In
Munchables, a project that had won an award in Blast's L2 "Big Bang" competition, was exploited for $62.5M by one of its own developers. In a chaotic sequence of events, the bulk of the funds were recovered within hours of the attack.
The team moved quickly to disclose the compromise on March 26, monitoring the attacker's movements and trying to halt the transfers as they happened. Speculation soon spread through the Web3 security community that Munchables may have unknowingly brought on a North Korean developer who never relinquished control of the project's smart contracts.

On-chain investigator ZachXBT then took an aggressive stance against the suspected insider, publicly naming them — an intervention that appears to have played a decisive role in the funds ultimately being returned.
This was the second exploit to hit a Blast-based protocol within a week, following the $4.8M loss suffered by Super Sushi Samurai just days earlier. Blast, still a relatively new chain, has already amassed $1.24B in TVL — surpassing Avalanche — making these early stumbles particularly concerning for a network growing so quickly. Whether Blast can shake off this rough start or faces further incidents that undermine confidence in the ecosystem remains to be seen.
Credit for details in this account goes to ZachXBT, Munchables, Pop Punk, quit.q00t.eth, and Pacman.
01Anatomy of the exploit
Evidence suggests the $62.5M theft was planned from the moment the malicious developer first deployed Munchables' smart contracts. Researcher quit.q00t.eth dug into the code and found that the contract was an upgradeable proxy, and that it had at one point been pointed to an unverified implementation address — a red flag that had gone unnoticed.
The contract was later upgraded again to a version containing proper checks that stopped users from withdrawing more than they had deposited. But before that fix went live, the attacker exploited the window to directly manipulate the contract's storage slots, crediting their own account with a deposit balance of 1,000,000 ETH.
In short: the insider hand-edited storage to fabricate an enormous ETH balance, swapped in an implementation that looked legitimate on the surface, then waited until the protocol's TVL was substantial before withdrawing the fabricated balance.
Attacker address: 0x6e8836f050a315611208a5cd7e228701563d09c5
Contract upgrade transaction (March 21): 0xea1d9c0d8de4280b538b6fe6dbc3636602075184651dfeb837cb03f8a19ffc4f
02The developer gets named
A few hours after the attack, ZachXBT publicly identified the suspected rogue developer. According to that research, four separate developers hired by Munchables and connected to the exploit were very likely the same individual operating under different identities — they had vouched for one another during hiring, routed payments to the same two exchange deposit addresses, and funded each other's wallets.
GitHub accounts linked to the case:
- NelsonMurua913
- Werewolves0493 (account no longer accessible)
- BrightDragon0719 (account no longer accessible)
- Super1114
Payment addresses:
- 0x4890e32a6A631Ba451b7823dAd39E88614f59C97
- 0x6BE96b68A46879305c905CcAFFF02B2519E78055
- 0x9976Fe30DAc6063666eEA87133dFad1d5ec27c5E
Exchange deposit addresses:
03Funds returned
Just 11 minutes after ZachXBT's post, Munchables announced that the developer had agreed to hand over the keys to the full set of stolen funds, no conditions attached. Commentator Duo Nine argued that ZachXBT's public exposure frightened the developer into returning access.
Roughly $60.5M was sent back to Munchables across three transactions:
- 0x69f271f90204ae993200f54676c922fe5ee3e5020a16ae34f589f52d923857f1
- 0x381d57aa2d959ff9580ad61cc6549ae3c026eed9ee5b2ea10f9601a186c49a13
- 0x62a148877957cbf1ae89cafa144496d99239ee900a3b90194249e6baaa3ddc2f
Pacman confirmed that the recovered funds had been placed into a multisig controlled by Blast's core contributors, and later thanked both ZachXBT and samczsun for their behind-the-scenes assistance.

04Open questions
Some in the community floated the possibility that the rogue developer had ties to North Korea's Lazarus Group, though this has not been officially confirmed and remains speculative regarding motive and method.
Separately, discussion emerged around rolling back the Blast chain entirely — an idea that immediately drew criticism on decentralization grounds. Once the funds were returned, the rollback proposal lost momentum, though it left behind a broader debate about what such a move would even mean for the chain's credibility.
An audit of the Munchables contracts had been completed in March 2024 by Entersof (audit document password: ESMunc@24!). As is often the case, an audit was of little help here, since a planted, malicious insider isn't the kind of threat a standard code review is built to catch.
The CEO of Pixecraft Studios noted separately that his own studio had briefly trial-hired the same developer back in 2022, ending the arrangement in under a month due to suspicious behavior. Following that experience, the studio overhauled its hiring process, now working only with vetted recruiters who background-check candidates, and recommends other crypto teams adopt similar screening rather than sourcing hires from open job boards.
The episode also reignited debate over doxxing within crypto: whatever the ethical trade-offs of exposing individuals' identities, the practice arguably functioned here as a real deterrent, pressuring the attacker into returning funds and helping protect the platform's users. Balancing privacy against accountability is likely to remain a persistent tension as the industry matures.
With ZachXBT actively pursuing leads, public discussion of potential state-level intervention via a rollback, and the developer left with no viable way to move the stolen funds without being tracked, the attacker's rapid capitulation is perhaps unsurprising. Still, the outcome could easily have gone differently — including the prospect of Blast attempting an actual chain rollback, assuming that were even technically possible.
Coming just days after Super Sushi Samurai, this marks the second security incident on Blast within a week, underscoring the need for other protocols on the network to reassess their defenses and stay alert to similar risks.
Get new scam files the moment we publish them — usually 2–3 emails a week.