CryptoReal
CASE FILE — Jan 16, 2025

Self-Transfer Exploit Drains $324K in stETH From The Idols NFT

An attacker exploited a flaw in The Idols NFT project's staking-reward logic by repeatedly sending transactions to themselves, draining approximately 97 stETH — roughly $324,000 — from the protocol before the team could intervene.

What happened

Researchers at Tikkala Security first flagged unusual activity in The Idols' IdolMain contract around midday on January 14th. The underlying issue was a flaw in the contract's _beforeTokenTransfer() function: whenever a transaction was structured so the sender and receiver addresses were identical, and the sender's token balance equaled exactly 1, the reward logic could be triggered repeatedly without the intended safeguards.

According to analysis from TenArmorAlert, the function handled these self-directed transfers by first clearing the sender's recorded claimedSnapshots and only afterward evaluating the reward claim for that same address. Because the claim history was wiped before the check ran, the contract lost track of rewards it had already paid out, allowing the same address to repeat the self-transfer and collect payouts over and over.

The attacker funded the exploit from Union Chain — initial funding transaction 0x26aba26511874128b2bf075c4d5f801b27a42082c1ce7aa25327f61fa0185981 — then carried out a series of self-referential transfers to accumulate stETH the protocol should never have released. One representative transaction is recorded here.

The Idols team acknowledged the exploit roughly two hours after the first alert and warned users away from interacting with the affected contract. By then, the attacker had already withdrawn approximately 97 stETH, worth about $324,000 at the time.

The attacker's address, 0xe546480138d50bb841b204691c39cc514858d101, is linked to an OpenSea profile, and the movement of the stolen funds can be traced through Metasleuth's flow-of-funds tool.

Project background

The Idols is a collection of 10,000 generative NFT portraits, each entitling its holder to a proportional share of ongoing stETH staking rewards generated by the protocol's treasury. That treasury was designed to be "monotonically increasing" — meaning the underlying stETH principal could never be withdrawn, only the staking yield it produced — intended to guarantee holders a lasting source of value.

That same reward-distribution design, meant to be the project's core selling point, turned out to be exactly what the attacker exploited.

The protocol had been audited in early 2022 by both CertiK and WhiteHat DAO, but neither review covered the specific contract addresses involved in this exploit — the codebase had changed in the interim, meaning the earlier audits never had a chance to catch the vulnerability. In total, 97 stETH was drained from a treasury structure explicitly built to never lose its principal.

The Idols NFT
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.