Close Menu
Computing.net
    Facebook X (Twitter) Instagram
    Computing.netComputing.net
    • News
      1. AI
      2. Crypto
      3. Gaming
      4. Hardware
      5. Security
      6. Software
      7. View All

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      AI Trading Bot Loses $441K in Crypto After Decimal Point Mistake

      February 23, 2026

      Tesla (TSLA) Stock: Goodbye Sedans, Hello Robots in Dramatic Production Shift

      January 29, 2026

      Palantir Technologies (PLTR) Stock: Why Bears May Be Wrong About Valuation Concerns

      January 29, 2026

      SUI Token Rallies 40% Following Major Staking Event and CME Futures Announcement

      May 12, 2026

      Chainlink (LINK) Surges to $10.40 as Network Activity Hits Eight-Month Peak

      May 12, 2026

      Dogecoin Whales Ramp Up Accumulation as DOGE Eyes Critical Breakout Levels

      May 12, 2026

      Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

      May 12, 2026

      Hamster Kombat: Unraveling TON’s Gaming Phenomenon

      August 7, 2024

      W-Coin: Exploring the Latest Telegram Tap-to-Earn Phenomenon

      August 7, 2024

      Hamster Kombat: 300 Million Players & Counting, HMSTR Token Airdrop Soon!

      July 31, 2024

      Hamster Kombat Developers Work with TON Team on Airdrop Solution

      July 30, 2024

      Nothing Expands Product Line with New AI Feature & Phone Update

      July 31, 2024

      Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

      August 6, 2024

      SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

      July 30, 2024

      OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

      July 30, 2024

      Hamster Kombat Players Face Growing Cybersecurity Threats

      July 25, 2024

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      Cookie Crumble: Google Halts Plans to Eliminate Third-Party Cookies in Chrome

      July 23, 2024

      Big Brother is Watching: Apple’s Creepy New Ad Urges iPhone Users to Ditch Chrome

      July 23, 2024

      Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

      May 12, 2026

      Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

      May 12, 2026

      GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

      May 12, 2026

      SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

      May 12, 2026
    • How To

      Batch Files: Tokens and Delimiters (FOR Loops)

      July 31, 2024

      Types of Ethernet Cabling & Electrical Low Voltage Wiring

      July 9, 2024

      What You Should Know About .JSON File Extension

      January 10, 2023

      Bkup File Extension

      November 19, 2022

      HEIC File Extension

      November 19, 2022
    • Office
      1. Excel
      2. Google Sheets
      3. View All

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024

      How to Remove Characters from Right in Excel

      July 30, 2023

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      Bullet Points in Google Sheets

      January 20, 2022

      Sort by Date in Google Sheets

      January 18, 2022

      Google Sheets Timestamp

      January 17, 2022

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024
    • Answers
    • About
    • Contact
    Facebook X (Twitter)
    Computing.net
    News

    Deprecated Contract Costs Scallop Protocol $142K on Sui Blockchain

    Oliver DaleBy Oliver DaleApril 27, 2026
    Twitter LinkedIn Email Telegram
    Twitter LinkedIn Email Telegram

    Contents:

    Toggle
    • Key Points
    • Scallop’s Immediate Response and Service Restoration
    • DeFi Security Landscape in April 2026

    Key Points

    • Scallop Protocol experienced a loss of approximately $142,000 (150,000 SUI) during an April 26, 2026 security breach
    • The breach focused on an abandoned V2 rewards contract originally deployed in November 2023
    • A vulnerability involving an uninitialized “last_index” variable enabled complete rewards pool drainage
    • Main protocol infrastructure and user deposits remained secure; normal operations continued after two hours
    • The individual responsible proposed returning 80% of the funds through a white-hat agreement

    Scallop Protocol, a lending platform operating on the Sui Network, experienced a security breach resulting in approximately $142,000 worth of SUI tokens being stolen on Sunday. The breach stemmed from vulnerabilities in an abandoned rewards contract.

    🚨 SECURITY INCIDENT NOTICE

    We have identified an exploit affecting a side contract related to Scallop’s sSUI spool rewards pool, resulting in a loss of approximately 150K SUI.

    The affected contract has been frozen. Our core contracts remain safe and only the sSUI rewards pool…

    — Scallop (@Scallop_io) April 26, 2026

    The security incident occurred on April 26, 2026. Scallop made a public announcement regarding the breach at 12:50 UTC through their official X account.

    The primary protocol infrastructure remained intact during the breach. The attacker focused their efforts on a legacy contract associated with Scallop’s sSUI spool, which manages reward distribution for SUI token depositors.

    The vulnerable contract was a V2 spool package that went live in November 2023. This means the contract had been active for over 17 months before the exploitation took place.

    On the Sui network, smart contracts become permanent once deployed. Previous versions remain accessible and executable unless developers implement specific version control barriers. This architectural characteristic transformed the outdated contract into a persistent vulnerability.

    The primary vulnerability centered on an uninitialized variable labeled “last_index.” This variable functions as a tracker for accumulated staking rewards. The absence of initialization during new account creation allowed the attacker to enter the staking pool and extract rewards calculated as though their participation dated back to the pool’s inception.

    The attacker deposited approximately 136,000 sSUI into the system. Over 20 months, the spool index had accumulated to roughly 1.19 billion.

    This differential enabled the attacker to assign themselves approximately 162 trillion reward points. The rewards mechanism converted these points at parity, resulting in the complete extraction of 150,000 SUI through a single transaction.

    The on-chain transaction identifier 6WNDjCX3W852hipq6yrHhpUaSFHSPWfTxuLKaQkgNfVL documents the withdrawal.

    Extracted tokens were immediately routed through a Sui-based mixing service, functioning similarly to Tornado Cash, which complicates fund recovery efforts.

    Scallop’s Immediate Response and Service Restoration

    Scallop’s engineering team disabled the compromised contract within minutes of detection. Primary lending and borrowing infrastructure remained operational throughout the incident. Depositor assets across all Scallop markets maintained complete security.

    The protocol announced full reimbursement of the loss from internal treasury reserves. User yield distributions will face no dilution.

    At 14:42 UTC, Scallop reactivated the main contracts. Standard withdrawal and deposit functionality returned to normal operation less than two hours following the initial breach.

    The individual behind the attack subsequently reached out to the team with a proposal to restore 80% of the extracted funds in return for white-hat bounty compensation. The team has initiated an investigation into how this vulnerability escaped detection during previous security audits conducted by OtterSec and MoveBit.

    DeFi Security Landscape in April 2026

    This incident arrives after a comparable breach affecting Volo Protocol earlier this month, which resulted in approximately $3.5 million in losses. Both situations involved secondary contracts rather than primary protocol infrastructure.

    April 2026 has recorded over $600 million in stolen cryptocurrency across 12 significant security incidents. Total losses for the month surpassed $750 million by mid-April.

    Kelp DAO and Drift Protocol represented approximately 95% of April’s total losses. The Kelp breach alone generated $177 million in uncollateralized debt on Aave.

    Scallop’s development team has yet to release a comprehensive post-incident analysis. They have committed to conducting a thorough audit of all remaining legacy contract packages.

    Neither the Sui Foundation nor Mysten Labs has issued an official response regarding this security incident.

    Share. Twitter LinkedIn Email Telegram
    Oliver Dale
    • Website
    • X (Twitter)
    • LinkedIn

    Editor-in-Chief of Computing.net and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact Oliver@blockonomi.com

    Related Posts

    Senate Releases Complete Clarity Act Text: Crypto Regulation Bill Faces Critical Vote

    May 12, 2026

    Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

    May 12, 2026

    Binance AI Systems Thwart $10.5 Billion in Cryptocurrency Fraud Attempts Over 15 Months

    May 12, 2026

    Galaxy Digital Partners with Sharplink on $125M Ethereum DeFi Yield Strategy

    May 12, 2026

    Kiyosaki’s 2026 Economic Forecast: His Investment Strategy for Silver, Bitcoin and Ethereum

    May 12, 2026

    Brent Crude Surges Past $100 Following Trump’s Dismissal of Iran Proposal

    May 11, 2026
    Add A Comment

    Comments are closed.

    Latest

    Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

    May 12, 2026

    Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

    May 12, 2026

    GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

    May 12, 2026

    SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

    May 12, 2026

    Trump Dismisses Iran Peace Proposal — Oil Markets React as Hormuz Remains Restricted

    May 12, 2026
    • Facebook
    • Twitter

    Latest Reviews

    Meta Platforms Shares Tumble 8% Despite Strong Q1 Performance Amid AI Investment Surge

    April 30, 2026

    Flush.com Review: Casino & Sportsbook With 275% Welcome Bonus

    March 7, 2026

    Katsubet Review: Crypto Casino With 300% Welcome Bonus & Free Spins

    March 7, 2026

    7Bit Review: Crypto Casino With 325% Bonus & 250 FS

    March 7, 2026

    Mega Dice Review: Crypto Casino With 200% Bonus & 50 Free Spins, Legit?

    March 7, 2026


    Home / Privacy Policy / Terms & Conditions

    Computing.net © 1996 - 2026 Kooc Media Ltd. All rights reserved. Registered Company No.05695741

    Type above and press Enter to search. Press Esc to cancel.