Tornado Cash user hacks SuperRare staking contract, steals $730K in RARE
A Tornado Cash user hacked the staking contract of NFT gallery firm SuperRare today, stealing roughly $730,000 worth of RARE tokens. Crypto security analysts Peckshield first noticed the substantial loss while Cyvers Alerts reported that the attacker had previously used crypto mixer Tornado Cash 186 days ago. SlowMist claims the exploit was caused by a faulty permission check in the “updateMerkleRoot function” that allowed the hacker to modify the staking contract and claim tokens for themselves. ALERTOur system has detected a malicious transaction targeting a @SuperRare staking contract. The attacker’s address, funded via @TornadoCash approximately 186 days ago, executed the exploit and gained 731K worth of $RARE. The stolen funds currently remain in the attacker’s… pic.twitter.com/9CZ6IG4b4B — Cyvers Alerts (@CyversAlerts) July 28, 2025 Read more: Roman Storm says he’s been ‘financially cancelled’ after payroll firm axe SuperRare is an NFT art fir...