There will be situations in your life where you can take advantage of someone. In those moments, whether you choose to do it or choose to be fair is the best judge of your character.
We aren’t animals. We were given the ability to be compassionate and understanding. It’s not a weakness to embrace it.
24-Hour Incident Update
Following our earlier communication, we want to share key, substantive findings from the first 24 hours of investigation. This is an on-going investigation. A full post-mortem will follow when these workstreams are complete. The findings below are what we can responsibly share now.
Tangentially, we are aware of rumors and FUD spreading and intend to address those directly with the evidence we present in our findings. First, this is not an inside job nor is there any team involvement; implications that the team is secretly selling tokens or anything of that nature is entirely false and can be proven empirically. Second and related, we have never engaged with Web3Port. Both ongoing rumors are entirely fabricated.
✅ The Details That Are Confirmed
1️⃣ The attack was not address poisoning of our transaction-construction workflow. Our earlier assessment that address poisoning was unlikely has been confirmed by direct forensic evidence. The team member who proposed the multisig transaction (Signer 1) signed the correct recipient address 0x70ae7D3DECfB4C3aE996fb1c07092566F73D5c15 at 03:17 UTC on May 27, during the internal verification call. The signed payload is preserved verbatim in the local device logs, with the correct address and correct amount.
2️⃣ The attack was a compromise of that signer's private key. A separate valid signature — for a different transaction with the attacker's address 0x70AE678b457C5E1b3fD7AD9537F234dFc1795C15 as recipient — was submitted to the Safe Transaction Service at 04:00 UTC, 43 minutes later. That second signature is cryptographically valid for the same wallet but does not appear in the Signer 1’s local device logs. The mechanism that explains this is that the attacker had independent possession of the private key and signed the substituted transaction from outside Signer 1’s infrastructure.
The remaining signers reviewed the queued transaction in the Safe interface. The attacker's address was specifically constructed to share the same first four and last four hex characters as the correct recipient — both begin with 0x70AE and end with 5C15. This vanity pattern is used to appear as the correct address in the Safe UI preview. Specifically generating these fake vanity addresses takes time and resources and implies premeditation and planning on the attacker’s end (more mention of this in point 4). Following confirmation the preview, the remaining signers signed the transaction. The on-chain execution followed at 17:59:24 UTC.
3️⃣ Funds are fully traced and currently parked on Ethereum. Within ~4 hours of execution, the attacker liquidated the stolen GUA on PancakeSwap, swept proceeds to an operational hub wallet 0xb292a7016c0008e786edca46459ccee063673afb, bridged the value to Ethereum via cross-chain protocols, and consolidated approximately 2,783.99 ETH into three cold-storage wallets that currently hold the funds with zero outflows:
- 0x111b78A86C16dBD4261FCb5C7D3A9dAF25E2b589
- 0x7b8f28Ff2E1D4DF2D8ddD1daBaFf8c3E58FE841C
- 0xfa4cb6add9da4a4b714541b98fd4b2e3da86b7c8
- A separate ~170,121 USDT was bridged out.
4️⃣ The attacker is using substantial, reusable infrastructure. The operational hub address and the three Ethereum cold-storage addresses are each surrounded by brute-forced lookalike "vanity twin" addresses that the attacker is seeding with fake transfer events using Unicode-spoofed token symbols (ETH, EṬH, ĖTḨ). The same vanity-address construction technique produced the address used against our project. The scale and pre-staging of this infrastructure indicates an industrialized operation rather than an opportunistic one-off attack.
We will continue to publish substantive updates as the investigation progresses, while protecting information that could compromise active workstreams. We continue to work closely with authorities, white hats, and tracing services. We thank the community for its patience.
We are investigating a security incident that occurred for the token, $GUA, through a suspected address poisoning attack on May 27, 2026, which has caused significant volatility on the token.
Initial findings indicate an address manipulation through a multisig transaction intended to release additional unlocked tokens into the airdrop claim contract, which allows users to claim unlocked airdrops.
The intended address for this is 0x70ae7D3DECfB4C3aE996fb1c07092566F73D5c15 (the intended address) but the resulting address the executed transaction sent to was 0x70AE678b457C5E1b3fD7AD9537F234dFc1795C15 (the hacker address).
The hacker address never had any interaction with any addresses associated with SUPERFORTUNE previously, so address poisoning as an attack vector is unlikely. Furthermore, internal operating procedures account for address poisoning attempts by matching addresses through several checks.
We are continuing to investigate the hack and will provide the community on an ongoing basis. We have contacted authorities and incident response teams to assist.
Reflecting on a fantastic run with the @MantaNetwork team. 🔱
Over the past 3 years, I worked as a Motion Designer, From bringing the brand to life on global billboards and event stages to crafting the product launches and website motion that defined our digital presence.
Grateful for the people, the pace, the trust to create, and leadership @superanonymousk@victorone111
Now open to new opportunities & collaborations.
Personal Update:
My time at @MantaNetwork has come to an end.
Over the last 2.6 years as Head of Ecosystem, I worked on building the developer ecosystem and over time ended up wearing multiple hats supporting founders internally, working closely with projects and representing Manta across global events.
During this time:
• Scaled the ecosystem to 124 deployed apps
• Engaged with and supported 520+ projects across the pipeline
• Represented Manta on 38 panels and 7 keynotes globally
Being the face of Manta as “Manta Man” around the world has been an unforgettable experience.
Grateful to have worked with incredible people across the space, and excited to see what’s next for Manta especially projects like @junkfun_ and @SUPERFORTUNE888 under the leadership of @superanonymousk and @victorone111
As for me: happy to connect with projects looking to strengthen their BD and Partnerships teams.
DMs always open.
I made a prediction at a conference years ago: the future of AI isn’t OpenAI, and no one cares about verification of their models. Because all models will be running locally on your devices. Starting with servers, then desktops, then laptops, and now phones.
Give it two years, they’ll be running locally in your glasses.
The new Qwen 3.5 by @Alibaba_Qwen running on-device on iPhone 17 Pro.
Qwen 3.5 beats models 4 times its size, has strong visual understanding, and can toggle reasoning on or off.
The 2B 6-bit model here is running with MLX optimized for Apple Silicon.
There’s a fundamental tradition during Chinese New Years that no one wants to miss out on: receiving Red Pockets. 🧧
We wanna give you some too. Join the @SUPERFORTUNE888 CNY Spring Fortune festivities to win some!
Happy Chinese New Year!
@SUPERFORTUNE888 kicks off the 2026 Year of the Horse with a massive New Year Event: Spring Fortune! 🥠
📅 Feb 10th – Feb 24th
💰 Total Rewards: $50,000+ up for grabs
We’re teaming up with @BNBCHAIN, @PANews, @fourdotmemezh, @EnHeng456, @QuickswapDEX, @TrustWallet, @MancerWork, @GoPlusSecurity, @mindnetwork_xyz to co-host this campaign, bringing the community together to start the Horse Year with super fortune. 🐎
Meanwhile, [Qi Purifier] bonus rewards will be active throughout the whole event!
📌 How to Participate
1️⃣ Visit the campaign page: https://t.co/yBcMatE0l4
2️⃣ Select a featured project / reward pool
3️⃣ Complete the tasks to unlock your share of $50,000+ in rewards
「Spring Fortune」 will be divided into 5 phases with progressive reward unlocks. Stay tuned to official announcements to join future rounds immediately.
Phase 1 Rewards
•QuickSwap | 400 USDT + $200 worth of $GUA
•PANews | Exclusive Swag + 800 USDT
•https://t.co/16yAxMi4EN | 800 USDT
•嗯哼 | 800 USDT
Start your 2026 with @SUPERFROTUNE888, fortune moves for those who answer the call. 🧧
Happy Chinese New Year!
@SUPERFORTUNE888 kicks off the 2026 Year of the Horse with a massive New Year Event: Spring Fortune! 🥠
📅 Feb 10th – Feb 24th
💰 Total Rewards: $50,000+ up for grabs
We’re teaming up with @BNBCHAIN, @PANews, @fourdotmemezh, @EnHeng456, @QuickswapDEX, @TrustWallet, @MancerWork, @GoPlusSecurity, @mindnetwork_xyz to co-host this campaign, bringing the community together to start the Horse Year with super fortune. 🐎
Meanwhile, [Qi Purifier] bonus rewards will be active throughout the whole event!
📌 How to Participate
1️⃣ Visit the campaign page: https://t.co/yBcMatE0l4
2️�� Select a featured project / reward pool
3️⃣ Complete the tasks to unlock your share of $50,000+ in rewards
「Spring Fortune」 will be divided into 5 phases with progressive reward unlocks. Stay tuned to official announcements to join future rounds immediately.
Phase 1 Rewards
•QuickSwap | 400 USDT + $200 worth of $GUA
•PANews | Exclusive Swag + 800 USDT
•https://t.co/16yAxMi4EN | 800 USDT
•嗯哼 | 800 USDT
Start your 2026 with @SUPERFROTUNE888, fortune moves for those who answer the call. 🧧