Infinite-Mint Bug Drains $4.8M From Blast Game Super Sushi Samurai
A liquidity pool belonging to Super Sushi Samurai, a game running on the Blast layer-2 network, was emptied of $4.8 million within hours of the project going live, sending its token price down 99.9%.
The first public warning came from a user known as Spreek, who flagged the unusual activity at around 14:00 UTC. The Super Sushi Samurai team replied within minutes, saying token transfers were being paused while the situation was investigated. Roughly half an hour later, the team followed up with more detail: "We have been exploited, it's mint related. We are still looking into the code. Tokens were minted and sold into the LP."

The mechanics resembled an earlier incident at Gamma Strategies, an Arbitrum-based protocol that suffered a comparable minting exploit earlier the same year, for a similar amount.
At the root of the exploit was a flaw in how the token contract handled transfers to oneself. Under normal operation, a transfer function deducts the sent amount from the sender's balance before crediting it to the recipient. According to a technical breakdown shared after the incident, the contract skipped that deduction whenever the sender and recipient addresses were identical — so instead of leaving the balance unchanged, a self-transfer simply doubled it.
By repeating this self-transfer trick, the attacker kept doubling their holdings and then sold the artificially inflated tokens into the pool, which is what produced the $4.8 million shortfall. The attacker needed only about an hour to turn an initial $35 into roughly $4.6 million.
On-chain data ties the exploit to an attacker contract at 0xDed85d83Bf06069c0bD5AA792234b5015D5410A9 and a controlling wallet at 0x6a89a8c67b5066d59bf4d81d59f70c3976facd0a. Three transactions carried out the drain:
- 0x80012bf784b83baaf28f5549a9f233cae5f70be7afcd8f594dc757d431ed93c4
- 0x62e6b906bb5aafdc57c72cd13e20a18d2de3a4a757cd2f24fde6003ce5c9f2c6
- 0xac3400e3d536ac23c10fdd2c06e1faf8d5de5b797df8433e9b5ab74b102a4e35

The money may not be gone for good, however. The address behind the drain later sent an on-chain message framing the incident as a whitehat rescue rather than theft, leaving contact details and stating that affected users should be reimbursed. Super Sushi Samurai said it had since reached out to the person responsible.
The token contract had gone through a security review by Verichains, documented in the project's own security notes, yet the infinite-mint pathway was not caught before launch. The episode adds to a familiar pattern across the sector: contracts that clear a formal audit still end up exploited through flaws the review process failed to surface, which keeps raising the question of how much confidence an "audited" label should actually inspire — and whether the auditors themselves warrant closer scrutiny when this keeps happening.
Get new scam files the moment we publish them — usually 2–3 emails a week.