Ted Hisokawa
Jun 16, 2026 17:58
Fireblocks detected and mitigated important zero-day flaws in SWEAT and HOT contracts on NEAR, safeguarding 22M customers from potential multi-million greenback losses.
Fireblocks has revealed its position in figuring out and mitigating two important zero-day vulnerabilities that would have price NEAR Protocol customers thousands and thousands of {dollars}. The issues had been found within the contracts of SWEAT, a token powering the Sweat Financial system ecosystem, and HOT, a Web3 governance token with over 22 million holders.
In late April 2026, Fireblocks’ blockchain monitoring flagged uncommon transactions on NEAR involving SWEAT tokens. Attackers had been draining wallets with out requiring personal keys, phishing hyperlinks, or consumer signatures. One sufferer alone misplaced 8.5 million SWEAT tokens in a single exploit, valued at $170,000 to $250,000. The issue stemmed from a lacking safety guard within the ft_resolve_transfer callback perform, which refunded token balances with out verifying the caller’s identification.
The exploit leveraged NEAR’s token normal (NEP-141), which makes use of ft_resolve_transfer to refund unused balances. In SWEAT’s implementation, this perform lacked NEAR’s #[private] macro, leaving it uncovered to public calls. Attackers exploited the flaw by crafting a malicious contract that tricked the system into issuing refunds on to their wallets. The consequence: thousands and thousands of tokens drained from victims’ accounts.
HOT Contract Flaw Uncovered
After patching SWEAT’s vulnerability, Fireblocks launched a broader investigation throughout NEAR’s ecosystem. Their proactive search uncovered the identical flaw in HOT, a governance token with over 22 million holders. The potential penalties had been extreme—attackers may have exploited the identical “empty refund” logic to mint limitless HOT tokens or drain consumer balances. Fireblocks reported the problem to HOT’s maintainers, who deployed a patch the identical day.
The stakes had been monumental. HOT’s ecosystem helps over 35 million customers and tons of of thousands and thousands of token transfers. A profitable exploit may have triggered large monetary losses and eroded confidence in NEAR’s infrastructure.
Broader Implications for Web3 Safety
Fireblocks’ swift motion highlights the rising stakes in blockchain safety. As AI instruments speed up the tempo of code evaluation, attackers can establish vulnerabilities in reside contracts quicker than ever. The identical instruments, nonetheless, can empower defenders to search out and repair flaws earlier than exploits happen.
For protocols like SWEAT, the results of such vulnerabilities are usually not simply monetary. SWEAT is a cornerstone of Sweat Financial system, a move-to-earn ecosystem that incentivizes bodily exercise by token rewards. The April 2026 exploit, which drained 13.71 billion SWEAT tokens (65% of provide), underscored the necessity for sturdy contract safety. Though consumer balances had been restored, the incident highlighted the fragility of token ecosystems reliant on good contract integrity.
As of June 16, 2026, SWEAT trades at $0.00071807, reflecting a 0.04481% decline within the final 24 hours. Its market cap stands at $8.93 million, underscoring the token’s restoration efforts post-exploit. HOT, in the meantime, prevented the same disaster because of Fireblocks’ intervention, preserving its ecosystem’s stability.
For Web3 builders, the lesson is evident: safety can’t be an afterthought. Because the arms race between attackers and defenders intensifies, proactive measures and rigorous audits are important to safeguarding consumer property and ecosystem belief.
Picture supply: Shutterstock