Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    US Inflation Hits 3.8% Here's the Exact Crypto Playbook Smart Money Is Using to Hedge It
    US Inflation Hits 3.8%: Here’s the Exact Crypto Playbook Smart Money Is Using to Hedge It
    Terra Luna Crash $60 Billion Lost, Do Kwon Jailed, Wall Street Sued
    The $60B Ghost: Four Years After Terra Luna’s Collapse, Do Kwon Is in Prison, and Wall Street Faces a Reckoning
    How the TXEX and DSJ Syndicates Built a $150M Empire on Trafficked Labor and Fabricated Lives
    $150M TXEX-DSJ Empire Exposed: 813 Fake Sites, Human Trafficking Camps, 276 Arrests
    CLARITY Act’s May 14 Senate Test: What Happens Next?
    CLARITY Act’s May 14 Senate Test: What Happens Next?
    40+ DeFi Protocols Shut Down in 2026 Inside the $770M Hack Crisis Reshaping Crypto
    40+ DeFi Protocols Shut Down in 2026: Inside the $770M Hack Crisis Reshaping Crypto
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

ShapeShift FOX Colony Loses $132K in Smart Contract Exploit on Arbitrum

Blockchain security firm Blockaid said other Colony Network deployments using the same architecture may also remain vulnerable.

Written By:
Sharmistha Suman

Reviewed By:
Shubham Soni

Last updated: 1 hour ago
Published 2 hours ago
Share
Last updated: 1 hour ago
Published 2 hours ago
ShapeShift FOX Colony Loses $132K in Smart Contract Exploit on Arbitrum

Key Highlights

  • ShapeShift’s FOX Colony lost around $132.7K in USDC and FOX tokens in an Arbitrum exploit.
  • Blockaid linked the attack to a vulnerability in the executeMetaTransaction function.
  • Other Colony Network deployments using the same architecture may also be vulnerable.

ShapeShift’s FOX Colony, a community initiative for FOX token holders, was exploited on Arbitrum, resulting in the loss of around $132.7K in USDC and FOX tokens. 

The incident was flagged by blockchain security firm Blockaid today, triggering a community alert. According to an X post by Blockaid, the attacker managed to drain funds from the Colony’s smart contracts on Arbitrum. The stolen assets mainly consisted of USDC stablecoins and FOX governance tokens.

Exploiter: 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28

Tx: https://t.co/qFrZZS1PA2

— Blockaid (@blockaid_) May 13, 2026

Such exploits mostly comprise smart contract vulnerabilities, compromised keys, or sophisticated phishing that escapes standard security measures.

Root cause of the exploit 

According to Blockaid’s analysis, the vulnerability is routed from a flaw where Colony executes the MetaTransaction function, which interacts with a self-call. The router can call function-automatically trusted calls, where msg.sender equals the contract’s own address. 

The attacker attacked this by meta-signing a set target transaction, repointed the colony’s resolver to a malicious contract, and thereafter used a delegate call to drain the funds. Blockaid alerted that every colony-network colony exposing executeMeta Transaction on top of EtherRouter, over any chain, is possibly vulnerable to the same attack vector. 

FOX Colony is ShapeShift’s community governance and participation program, permitting FOX token holders to stake, vote, and engage in ecosystem activities. The exploit targeted one of these colony contracts on Arbitrum.

The exploiter’s address associated with the primary drain is 0xeed236Afb6967f74099a0a6bf078BC6b865fbf28. As per the reports, another related exploit on similar instances withdrew an additional $50k soon after. 

As of now, ShapeShift hasn’t released any official statement regarding the recovery plans, compensation for affected users, or immediate mitigation steps. The core ShapeShift exchange platform is still operational, but optimism regarding the Colony program may be impacted.

Arbitrum network vulnerability

Another DeFi protocol on the Arbitrum network, named Aurellion Labs, was compromised yesterday. Aurellion Labs faced a hacker attack worth about $455,003 USDC, as revealed by blockchain security company SlowMist. 

The hack occurred when the attacker with the address 0x9f4…d5ca exploited the unprotected initialize(address) function of the SafeOwnable Facet of the diamond proxy contract of the protocol. 

As there was no storage slot updating in the _initialized variable, the hacker managed to reinitialize the contract, take ownership, and inject malicious code using diamondCut functionality. This helped drain the approved USDC from several victim wallets.

Users advised to keep themselves updated

Individuals using services in the Colony projects are recommended not to engage with any suspicious contracts, revoke approvals when necessary, and keep themselves updated with official communications regarding their safety.

Despite being relatively small compared to some of the latest events, this exploit, worth $132,700, is another demonstration of the existing security threats associated with smart contracts. In the meantime, the ongoing incident raises awareness about the importance of auditing systems for possible exploits and vulnerabilities. 

The response of the project team to this exploit will be under careful observation by the entire Arbitrum and ShapeShift communities.

Also Read: Bitwise Goes On-Chain With Jupiter Lend’s First Institutional Market

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Sharmistha Suman - Crypto Journalist
By Sharmistha Suman
 
A crypto writer with a strong foundation in storytelling and digital media, Sharmistha holds a Bachelor’s degree in Creative Writing and a Master’s in Digital Journalism. Since entering the crypto industry in 2022, she has been actively covering developments across blockchain, digital assets, and emerging financial technologies. Her work focuses on breaking down complex topics into clear, engaging narratives, helping readers stay informed in a fast-evolving space.
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Lite Strategy Funds Buybacks With Covered Call Income and LTC in Q3
Lite Strategy Funds Buybacks With Covered Call Income and LTC in Q3
AARP Backs CLARITY Act Provision Targeting Crypto ATM Fraud
AARP Backs CLARITY Act Provision Targeting Crypto ATM Fraud
Ledger Halts IPO Plans Despite Continued U.S. Expansion
Ledger Halts IPO Plans Despite Continued U.S. Expansion
Upbit Listing Sends Superform (UP) Surging Nearly 80% Within Hours
Upbit Listing Sends Superform (UP) Surging Nearly 80% Within Hours
Google Exposes How Hackers Are Using AI to Target Crypto and Beyond 
Google Exposes How Hackers Are Using AI to Target Crypto and Beyond 

Find Us on Socials

You may also like

Immunefi Moves to Rescue Bug Bounty Programs After Code4rena Exit

Immunefi Moves to Rescue Bug Bounty Programs After Code4rena Exit

$1.88M Drained from Transit Finance: Stolen DAI Sits in Fresh ETH Wallet

$1.88M Drained from Transit Finance: Stolen DAI Sits in Fresh ETH Wallet

Code4rena Announces Wind Down After Securing Billions in DeFi

Code4rena Announces Wind Down After Securing Billions in DeFi

Aave CEO Backs CLARITY Act Ahead of Senate Banking Committee Markup

Aave CEO Backs CLARITY Act Ahead of Senate Banking Committee Markup

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information