Botched Proxy Upgrade Traps $20 Million in POL, and Nobody Will Say Whose Project It Is
An anonymous presale project appears to have locked roughly $20 million worth of POL tokens inside its own smart contract after a botched proxy upgrade wiped out the contract's admin and upgrade permissions — and more than a week later, no one has publicly claimed responsibility for the project or the funds.
01A Late-Night Mistake, Live in Public

The unraveling played out in the Ethereum Security Telegram channel in the early hours of September 13. A user identifying themselves as "Bruce Lee" posted asking for help: "Hey Guys I meet some problem. My contacts fund cannot be withdrawn. About 22m."
The underlying issue, as it was later described in the channel, was straightforward: a proxy upgrade had pointed the contract to the wrong implementation address, and in doing so wiped out the admin and upgrade roles needed to fix it. With those roles gone, the contract had no path left to reverse the mistake. At current prices, the frozen balance — 77.098 million MATIC/POL — was worth about $20 million.
02Piecing Together Who Was Behind It
Researcher YannickCrypto laid out an initial theory on Twitter/X: a presale that had collected 77 million POL, tentatively tied to the account @JUDAOGlobal (with the caveat that the connection wasn't confirmed), had failed to reinitialize the contract when swapping in a new implementation contract — resulting in roughly $22,000,000 becoming inaccessible.
That tentative identification traced back to a single Twitter reply containing account-opening instructions that listed the following as a "Vault" address:
0x7D341e757f893e1a13D40370d0F6065ca9c4777E
That address corresponds to a proxy contract that ended up holding the millions in POL now stuck in limbo. Because the project behind it has never been publicly confirmed, presale participants reportedly have no clear way of knowing what became of the money they put in.
03The Telegram Thread Unravels
As the channel absorbed the news, "Bruce Lee" asked for the original message to be deleted, writing that the disclosure was "bad news for our users." YannickCrypto's reply was blunt: "bro you locked ALL FUNDS of your users, you have other problems."
Pressed further, "Bruce Lee" tried to shift blame to a predecessor: "Not me. The prev dev, he is too tired when upgrading this contract. Set a wrong contract." Whether that "previous developer" was a real person or a convenient excuse was never established. YannickCrypto summarized the explanation simply as: "I mean the dev was tired."
The channel's reaction turned into dark humor. One participant suggested launching a memecoin to cover the story, while another referenced "Slerf" — the earlier Solana incident in which a developer accidentally burned millions of dollars in tokens by clicking the wrong button. Later, Mudit Gupta floated a half-joking recovery plan: a governance proposal bribing POL stakers to help recover the funds, to which someone replied simply, "Pol wars." Getting Polygon's governance to act on behalf of an unidentified, seemingly incompetent project was treated in the channel as a non-starter.
04Radio Silence
In the days since, there has been no public statement, blog post, or recovery plan from whatever team was running the project. The only trace remains the contract address itself:

0x7D341e757f893e1a13D40370d0F6065ca9c4777E
That address currently sits unlabeled on Arkham Intelligence, tagged only as "Fundpool (Proxy)," holding upward of $20 million in POL.
Security researcher Zilayo described JUDAO as effectively a black box: its Twitter account shows little recent activity and no way to make contact. Rekt News contacted JuCoin Labs, which had previously announced a partnership with JUDAO, but received no response.
That silence has fed speculation about whether this was pure negligence or something else — the possibility, floated by some in the community, that the project was never intended to return user funds at all, and that whoever built it ended up locking themselves out along with everyone else.
If the presale was genuine, its participants are presumably still unaware that their contribution is now sitting frozen on-chain, with no tokens forthcoming. As things stand, it's unclear which party bears the label of victim here — the presale participants, the anonymous team, or the developer whose late-night upgrade set the whole thing in motion. Anyone with information that could identify the project behind the address is encouraged to come forward.
Get new scam files the moment we publish them — usually 2–3 emails a week.