An attacker drained approximately 5.24 million ENJ, worth about $142,000 at recent spot prices, from Enjin’s legacy Ethereum ERC-1155 Crypto Items platform on August 25, 2026. The exploit moved value-backed items from roughly 52 unrelated wallets in a single transaction before melting them to redeem their ENJ backing from the platform reserve. Security monitor Defimon said a malicious transfer adapter bypassed owner-approval checks, although possible storage-collision and initialization flaws have not been confirmed as the root cause. The incident appears limited to items routed through the vulnerable adapter; there is no indication that Enjin’s core ERC-1155 contracts, Enjin Blockchain Layer 1 or users’ ENJ wallets were compromised. Enjin has not publicly addressed the incident, and the attacker’s externally owned account continued to hold the funds at the time of writing.