Enjin Coin platform exploit drains 5.24 million ENJ from 52 addresses

An attacker drained approximately 5.24 million ENJ, worth about $142,000 at recent spot prices, from Enjin’s legacy Ethereum ERC-1155 Crypto Items platform on August 25, 2026. The exploit moved value-backed items from roughly 52 unrelated wallets in a single transaction before melting them to redeem their ENJ backing from the platform reserve. Security monitor Defimon said a malicious transfer adapter bypassed owner-approval checks, although possible storage-collision and initialization flaws have not been confirmed as the root cause. The incident appears limited to items routed through the vulnerable adapter; there is no indication that Enjin’s core ERC-1155 contracts, Enjin Blockchain Layer 1 or users’ ENJ wallets were compromised. Enjin has not publicly addressed the incident, and the attacker’s externally owned account continued to hold the funds at the time of writing.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.