A vulnerability in Monad’s airdrop claim system allowed attackers to bind rewards without confirmation, leading to repeated failed transactions and massive gas fee losses.
On Nov. 25, a participant in Monad’s MON token airdrop lost over $112,000 to gas fees after hundreds of failed on-chain transactions. SlowMist’s founder revealed a flaw in the airdrop claim page that enabled attackers to bind rewards to their own wallets without user confirmation. The exploit caused the user to repeatedly attempt claims that never succeeded, accruing substantial gas costs and nullifying the airdrop’s value.