Adshares bridge-minter compromised; attacker minted ~1M fake wADS tokens and extracted $628K via Uniswap V4.
Security & Exploits ·
The Adshares bridge-minter was compromised on May 15, 2026, resulting in approximately $628K in losses. An attacker used the compromised bridge-minter EOA to sign three wrapTo() calls on the WrappedADS contract, minting a total of roughly 1M wADS tokens across two transfers of 99,999.93 and one of 999,999.94. Each call referenced native block-message transaction IDs that do not exist on the canonical Adshares chain, indicating the mints lacked legitimate cross-chain backing.
The attacker then liquidated the fraudulently minted wADS tokens through Uniswap V4's UniversalRouter, extracting approximately 148.5469 ETH and $304,995 USDC. The attacker's Ethereum address facilitated the dump, while a corresponding native account on the Adshares chain was also identified in connection with the exploit.
The precise mechanism by which the bridge-minter EOA was compromised—whether through key theft, social engineering, or contract vulnerability—remains unclear. Recovery prospects and whether any funds can be frozen or recovered through the liquidity pools or exchanges involved have not been reported.