How a Legacy Proxy Contract Let an Outsider Claim Wintermute's Misdirected 20M OP
Wintermute, the market-making firm, ended up losing 20 million OP tokens - worth roughly $27.6 million at the time - after a botched token transfer left the funds sitting at an address nobody actually controlled.
The tokens were part of an arrangement in which the Optimism Foundation would supply OP to Wintermute so the firm could act as a market maker in the run-up to the OP token's public launch. For the transfer, Wintermute supplied the address of its Ethereum multisig as the destination on Optimism - not realizing that this address was not one the firm actually held on that network.

According to the Optimism Foundation's own account, Wintermute confirmed receipt of two preliminary transfers - 1 OP and then 1 million OP - without ever verifying it could actually access funds sent to that address. The bulk of the transfer, 19 million OP, followed shortly after on May 27.
Per Wintermute's own statement, the firm alerted the Optimism Foundation to the error on May 30. Even so, the OP token launched as scheduled on June 1, with close to 10% of the tokens due to enter circulation parked at an address under no one's control.
On June 5, an unknown party seized the unclaimed tokens.
The mechanism behind the takeover
Research credited to yoav.eth, kelvinfichter and banteg later reconstructed how the funds became accessible to a stranger.
Once transferred, the tokens sat exposed: the destination address matched a Gnosis Safe proxy that existed on Ethereum mainnet, but no equivalent contract had ever been deployed to that address on Optimism. Claiming it as a standard externally-owned account was impossible without the private key - but there was a separate path in: anyone capable of deploying a Gnosis Safe proxy to that exact address on Optimism could take ownership of it. Pulling that off is far from straightforward, however.
Wintermute later explained that, having consulted with both the Optimism and Safe teams, it had concluded the tokens were likely recoverable and that no one else could reach them first. The plan called for a single, high-risk retrieval attempt with Safe's support, targeted for June 7 - "the assumption that the funds can only be recoverable by Wintermute proved to be false."
The root cause traced back to how Wintermute's mainnet Safe had been set up back in 2020, using an older version of the ProxyFactory contract that relies on Solidity's legacy create opcode rather than create2. Under create, the resulting proxy address depends purely on the deploying factory's address and its transaction nonce - meaning the exploiter could repeatedly deploy new proxies on Optimism, assigning themselves as owner each time, until the nonce lined up with the value that had produced Wintermute's address on mainnet.
That match was reached by deploying batches of 162 proxies at a time, culminating in the transaction that finally reproduced the correct address.
The exploiter's address was used to deploy the modified ProxyFactory contract, and had itself been funded via Tornado Cash on June 1.
Wintermute's Ethereum multisig, 0x4f3a120e72c76c22ae802d129f599bfdbc31cb81, and the compromised Optimism address share the same identifier.
Where the funds went
So far, 1 million OP has moved to the exploiter's externally-owned account and been swapped for 720 ETH, while a further 1 million OP was sent to an address belonging to Vitalik Buterin.
The sequencing of events drew scrutiny from yoav.eth, who pointed out that the attacker's contract had been funded through Tornado Cash seven days ahead of the hijack, then sat idle for four days after deployment before the proxy takeover was finally executed - an odd delay if the goal was simply to secure the loot as fast as possible.
The remaining 18 million OP had not been moved at the time of writing, leaving open whether that reflects a lack of liquidity to offload such a large position or a possible intent to return the funds. Wintermute itself is not counting on the latter: in its statement, the firm said there was hope the incident could turn out to be a whitehat action, in which case the remainder would be recoverable, "however we are currently operating under the premise that it is not the case."

In the interim, the Optimism Foundation has supplied Wintermute with an additional 20 million OP so the firm could still fulfill its original market-making mandate.
Wider implications
Beyond the direct loss to Wintermute, the episode raised governance concerns for Optimism more broadly. Having nearly 10% of OP's circulating supply sitting with an unidentified party is a risk the Foundation has publicly acknowledged, and the idea of using a network upgrade to freeze the movement of those specific tokens would set an uncomfortable precedent if it were ever invoked.
Notably, the misconfigured address had already been flagged publicly on the very day OP launched, but the warning appears to have gone largely unnoticed within the community. Since that post came hours after the exploiter's contract had already been funded, it's unlikely to have been the trigger for the eventual attack.
Replacing the lost 20 million OP is unlikely to strain a market maker of Wintermute's size financially, but the underlying lapse remains notable: the misdirected tokens sat exposed at an address no one controlled for nine full days before they were claimed.
Get new scam files the moment we publish them — usually 2–3 emails a week.