Gondi NFT lending protocol exploited via approval vulnerability in Purchase Bundler contracts; NFTs not in active loans at risk.
Security & Exploits ·
Gondi, an NFT lending protocol, disclosed a security incident affecting its Purchase Bundler contracts stemming from an approval vulnerability. The exploit targets NFTs that are not currently held as collateral in active loans, while NFTs pledged as security in ongoing loans appear unaffected at this time. The protocol has identified six affected contract addresses across Ethereum Mainnet and HyperEVM.
In response, Gondi is instructing users to immediately revoke approvals for the compromised contracts and suspend all platform activity until the team confirms safety. Users with expiring loans are directed to seek assistance through Discord support tickets rather than interact with the platform directly, and the protocol has explicitly warned against initiating loan repayments until further notice.
The scope of the exploit and the number of affected NFTs remain undisclosed. Gondi indicated it would provide additional updates once the situation is fully assessed and the platform is deemed safe to resume normal operations.