Enjin's ERC-1155 adapter vulnerability allowed attacker to drain $142K by bypassing approval checks on per-item transfer handlers across 52 holders.
Security & Exploits ·
Enjin's ERC-1155 adapter mechanism on Ethereum became the vector for a vulnerability that enabled the theft of approximately 5.24 million ENJ tokens valued at around $142,000. The platform allows individual items to route transfers through per-item adapter contracts; an attacker exploited this by registering a malicious adapter that bypassed owner-approval checks, allowing their exploit contract to call transferFrom on items held across roughly 52 unrelated wallets without requiring setApprovalForAll authorization from those holders.
Once the tokens were extracted via legitimate-appearing TransferSingle events, the attacker called the melt() function on each stolen item to redeem its 500-ENJ backing from the platform's reserve. The drained funds—totaling approximately 5.24 million ENJ—were forwarded to the attacker's address.
The vulnerability centered on the adapter architecture's failure to enforce approval requirements at the per-item level, allowing transfers to proceed without holder consent. It remains unclear whether the issue stems from a flaw in Enjin's adapter interface design, insufficient validation in the platform's melt mechanism, or both. No statement from Enjin regarding remediation or recovery has been provided in the available material.